Количество 2 531
Количество 2 531
GHSA-jpf2-9ppp-2c49
Moodle has insufficient access control
GHSA-jp4g-r8c9-3534
Moodle Blind SSRF Risk in /badges/mybackpack.php
GHSA-jjhx-5jff-rc8m
Moodle Improper Privilege Management
GHSA-jj3p-6mw3-6qmm
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").
GHSA-jj3j-mhgc-g4m4
Moodle cross-site scripting (XSS) vulnerability
GHSA-jgqm-rhq8-wrjr
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
GHSA-jgqm-9mm3-4p7g
Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.
GHSA-jg4f-8w9x-jv35
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
GHSA-jfrg-9hpq-9hvp
Improper Access Control in moodle
GHSA-jcrj-x36p-h9f6
Moodle Open Redirect in Calendar Set Page
GHSA-jcrj-gmr6-p5j8
Moodle Allows Modification of Constants
GHSA-j9cw-5cpj-9qj5
Moodle has a Hidden Functionality vulnerability
GHSA-j98x-965h-9v2h
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
GHSA-j8wr-7xxj-c2fr
Moodle Private files uploaded via incoming mail processing could bypass quota restrictions
GHSA-j822-x5gg-5r56
Moodle allows users to retrieve information they did not have permission to access
GHSA-j5xf-gv89-g422
Moodle Cross-site Scripting vulnerability
GHSA-j5rc-cr5w-vfg6
Moodle Session Fixation vulnerability
GHSA-j4mr-vc54-h5pc
Moodle cross-site scripting (XSS) vulnerability
GHSA-j465-7mp6-3xg3
Moodle places a session key in a URL
GHSA-j3x5-cwfj-pfcw
Moodle does not force password changes for autosubscribed users
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-jpf2-9ppp-2c49 Moodle has insufficient access control | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
GHSA-jp4g-r8c9-3534 Moodle Blind SSRF Risk in /badges/mybackpack.php | CVSS3: 10 | 0% Низкий | около 3 лет назад | |
GHSA-jjhx-5jff-rc8m Moodle Improper Privilege Management | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-jj3p-6mw3-6qmm A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app"). | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-jj3j-mhgc-g4m4 Moodle cross-site scripting (XSS) vulnerability | 0% Низкий | около 3 лет назад | ||
GHSA-jgqm-rhq8-wrjr admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability. | 0% Низкий | около 3 лет назад | ||
GHSA-jgqm-9mm3-4p7g Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page. | 0% Низкий | больше 3 лет назад | ||
GHSA-jg4f-8w9x-jv35 Moodle Authenticated LFI risk in some misconfigured shared hosting environments | CVSS3: 5.9 | 0% Низкий | около 1 года назад | |
GHSA-jfrg-9hpq-9hvp Improper Access Control in moodle | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-jcrj-x36p-h9f6 Moodle Open Redirect in Calendar Set Page | 0% Низкий | около 3 лет назад | ||
GHSA-jcrj-gmr6-p5j8 Moodle Allows Modification of Constants | 0% Низкий | около 3 лет назад | ||
GHSA-j9cw-5cpj-9qj5 Moodle has a Hidden Functionality vulnerability | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-j98x-965h-9v2h Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough | 0% Низкий | больше 3 лет назад | ||
GHSA-j8wr-7xxj-c2fr Moodle Private files uploaded via incoming mail processing could bypass quota restrictions | CVSS3: 4.2 | 0% Низкий | около 3 лет назад | |
GHSA-j822-x5gg-5r56 Moodle allows users to retrieve information they did not have permission to access | CVSS3: 6.5 | 0% Низкий | 9 месяцев назад | |
GHSA-j5xf-gv89-g422 Moodle Cross-site Scripting vulnerability | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
GHSA-j5rc-cr5w-vfg6 Moodle Session Fixation vulnerability | 0% Низкий | около 3 лет назад | ||
GHSA-j4mr-vc54-h5pc Moodle cross-site scripting (XSS) vulnerability | 0% Низкий | около 3 лет назад | ||
GHSA-j465-7mp6-3xg3 Moodle places a session key in a URL | 0% Низкий | около 3 лет назад | ||
GHSA-j3x5-cwfj-pfcw Moodle does not force password changes for autosubscribed users | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу