Количество 2 511
Количество 2 511
GHSA-mg54-p2wj-5ph7
moodle: IDOR when fetching report schedules
GHSA-m98q-q59p-r9fv
Moodle open redirect vulnerability
GHSA-m97f-x4mr-4x3q
Moodle vulnerable to Cross-Site Request Forgery
GHSA-m939-6pxj-m7xx
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
GHSA-m8qh-hx4c-h9hr
Moodle has a CSRF risk in Brickfield tool's analysis request action
GHSA-m8f5-9wg8-2c3h
Moodle multiple cross-site scripting (XSS) vulnerabilities
GHSA-m882-j7gq-v9p7
Moodle allows attackers to obtain sensitive category-detail information
GHSA-m7cc-6vhg-39wr
Moodle improper access control
GHSA-m63h-q4x3-6hwj
Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class
GHSA-m55g-vpgh-vw7c
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
GHSA-m434-m5pv-p35w
Insufficient user authorization in Moodle
GHSA-m3xp-4hf3-qfpp
Moodle allows remote attackers to obtain sensitive information
GHSA-m38p-4c43-vjrc
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.
GHSA-m37g-mwcg-7j7v
Moodle Improper Encoding or Escaping of Output
GHSA-m34m-fgh4-v7cx
Moodle External blog editing takeover
GHSA-m2pf-4pf8-45j2
Moodle allows remote authenticated users to cause a denial of service (invalid database records)
GHSA-m2f7-57gp-v34q
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.
GHSA-jq7x-gm9r-v8m7
Moodle allows attackers to obtain sensitive information
GHSA-jpf2-9ppp-2c49
Moodle has insufficient access control
GHSA-jp4g-r8c9-3534
Moodle Blind SSRF Risk in /badges/mybackpack.php
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-mg54-p2wj-5ph7 moodle: IDOR when fetching report schedules | CVSS3: 4.3 | 0% Низкий | 9 месяцев назад | |
GHSA-m98q-q59p-r9fv Moodle open redirect vulnerability | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-m97f-x4mr-4x3q Moodle vulnerable to Cross-Site Request Forgery | 0% Низкий | около 3 лет назад | ||
GHSA-m939-6pxj-m7xx Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters. | 1% Низкий | около 3 лет назад | ||
GHSA-m8qh-hx4c-h9hr Moodle has a CSRF risk in Brickfield tool's analysis request action | 0% Низкий | 4 месяца назад | ||
GHSA-m8f5-9wg8-2c3h Moodle multiple cross-site scripting (XSS) vulnerabilities | 0% Низкий | около 3 лет назад | ||
GHSA-m882-j7gq-v9p7 Moodle allows attackers to obtain sensitive category-detail information | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-m7cc-6vhg-39wr Moodle improper access control | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-m63h-q4x3-6hwj Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class | 1% Низкий | около 3 лет назад | ||
GHSA-m55g-vpgh-vw7c A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-m434-m5pv-p35w Insufficient user authorization in Moodle | CVSS3: 3.8 | 0% Низкий | больше 3 лет назад | |
GHSA-m3xp-4hf3-qfpp Moodle allows remote attackers to obtain sensitive information | 0% Низкий | около 3 лет назад | ||
GHSA-m38p-4c43-vjrc SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt. | 0% Низкий | около 3 лет назад | ||
GHSA-m37g-mwcg-7j7v Moodle Improper Encoding or Escaping of Output | CVSS3: 4.9 | 0% Низкий | почти 3 года назад | |
GHSA-m34m-fgh4-v7cx Moodle External blog editing takeover | CVSS3: 6.3 | 0% Низкий | около 3 лет назад | |
GHSA-m2pf-4pf8-45j2 Moodle allows remote authenticated users to cause a denial of service (invalid database records) | 0% Низкий | около 3 лет назад | ||
GHSA-m2f7-57gp-v34q Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request. | 0% Низкий | около 3 лет назад | ||
GHSA-jq7x-gm9r-v8m7 Moodle allows attackers to obtain sensitive information | 0% Низкий | около 3 лет назад | ||
GHSA-jpf2-9ppp-2c49 Moodle has insufficient access control | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
GHSA-jp4g-r8c9-3534 Moodle Blind SSRF Risk in /badges/mybackpack.php | CVSS3: 10 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу