Количество 2 712
Количество 2 712
GHSA-hpwm-84h5-vqr8
Moodle Setting for blocked hosts list can be bypassed with multiple A record hostnames
GHSA-hpmv-wvq3-gj27
Moodle cross-site request forgery (CSRF) vulnerability
GHSA-hp4v-c3h7-rwmx
mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.
GHSA-hjrj-7wcj-7j3c
Moodle sensitive information disclosure
GHSA-hjgc-jxjc-8v9j
Moodle reflected XSS via H5P error message
GHSA-hj48-8q8c-q7g9
Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter.
GHSA-hhxf-w8hj-43w6
Moodle vulnerable to Cross-site Scripting
GHSA-hhq7-jf2p-hw9c
Moodle multiple cross-site request forgery (CSRF) vulnerabilities
GHSA-hh52-g5c4-wprh
Moodle may allow authenticated users to enumerate other user's names via learning plans page
GHSA-hgw3-h5hf-vjv2
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
GHSA-hcm6-q6pc-xfhm
Moodle has an authorization logic flaw
GHSA-hchv-4gm2-gf5h
mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.
GHSA-h9w8-4376-j344
Moodle does not properly validate module instance id
GHSA-h8vc-v44p-5r2q
Moodle provides calendar-event data without considering whether an activity is hidden
GHSA-h8m4-h385-qhqv
Moodle Cross-site Scripting
GHSA-h7xp-7fjp-ghhc
moodle Improper Access Control
GHSA-h7h6-fwpv-ggvx
Moodle contains Stored XSS via ID number user profile field
GHSA-h798-h7ff-93xv
Moodle Arbitrary Redirect
GHSA-h77r-rp97-7rv4
Privilage Escalation in moodle
GHSA-h75f-hjcr-cvh8
Moodle multiple cross-site request forgery (CSRF) vulnerabilities
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-hpwm-84h5-vqr8 Moodle Setting for blocked hosts list can be bypassed with multiple A record hostnames | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-hpmv-wvq3-gj27 Moodle cross-site request forgery (CSRF) vulnerability | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-hp4v-c3h7-rwmx mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate. | 1% Низкий | около 4 лет назад | ||
GHSA-hjrj-7wcj-7j3c Moodle sensitive information disclosure | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-hjgc-jxjc-8v9j Moodle reflected XSS via H5P error message | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-hj48-8q8c-q7g9 Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-hhxf-w8hj-43w6 Moodle vulnerable to Cross-site Scripting | 2% Низкий | около 4 лет назад | ||
GHSA-hhq7-jf2p-hw9c Moodle multiple cross-site request forgery (CSRF) vulnerabilities | 1% Низкий | около 4 лет назад | ||
GHSA-hh52-g5c4-wprh Moodle may allow authenticated users to enumerate other user's names via learning plans page | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
GHSA-hgw3-h5hf-vjv2 Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface. | 2% Низкий | около 4 лет назад | ||
GHSA-hcm6-q6pc-xfhm Moodle has an authorization logic flaw | CVSS3: 5.4 | 0% Низкий | 6 месяцев назад | |
GHSA-hchv-4gm2-gf5h mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum. | 1% Низкий | около 4 лет назад | ||
GHSA-h9w8-4376-j344 Moodle does not properly validate module instance id | 1% Низкий | около 4 лет назад | ||
GHSA-h8vc-v44p-5r2q Moodle provides calendar-event data without considering whether an activity is hidden | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-h8m4-h385-qhqv Moodle Cross-site Scripting | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-h7xp-7fjp-ghhc moodle Improper Access Control | CVSS3: 4 | 1% Низкий | около 4 лет назад | |
GHSA-h7h6-fwpv-ggvx Moodle contains Stored XSS via ID number user profile field | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-h798-h7ff-93xv Moodle Arbitrary Redirect | 2% Низкий | около 4 лет назад | ||
GHSA-h77r-rp97-7rv4 Privilage Escalation in moodle | CVSS3: 7.5 | 2% Низкий | больше 5 лет назад | |
GHSA-h75f-hjcr-cvh8 Moodle multiple cross-site request forgery (CSRF) vulnerabilities | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу