Количество 2 470
Количество 2 470
CVE-2023-5542
Students in "Only see own membership" groups could see other students ...

CVE-2023-5540
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

CVE-2023-5540
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
CVE-2023-5540
A remote code execution risk was identified in the IMSCP activity. By ...

CVE-2023-5539
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

CVE-2023-5539
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
CVE-2023-5539
A remote code execution risk was identified in the Lesson activity. By ...

CVE-2023-30944
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.

CVE-2023-30944
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
CVE-2023-30944
The vulnerability was found Moodle which exists due to insufficient sa ...

CVE-2023-30943
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

CVE-2023-30943
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
CVE-2023-30943
The vulnerability was found Moodle which exists because the applicatio ...

CVE-2022-45152
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.

CVE-2022-45152
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
CVE-2022-45152
A blind Server-Side Request Forgery (SSRF) vulnerability was found in ...

CVE-2022-40316
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

CVE-2022-40316
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
CVE-2022-40316
The H5P activity attempts report did not filter by groups, which in se ...

CVE-2022-40315
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2023-5542 Students in "Only see own membership" groups could see other students ... | CVSS3: 3.3 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2023-5540 A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. | CVSS3: 4.7 | 2% Низкий | больше 1 года назад |
![]() | CVE-2023-5540 A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. | CVSS3: 4.7 | 2% Низкий | больше 1 года назад |
CVE-2023-5540 A remote code execution risk was identified in the IMSCP activity. By ... | CVSS3: 4.7 | 2% Низкий | больше 1 года назад | |
![]() | CVE-2023-5539 A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. | CVSS3: 4.7 | 2% Низкий | больше 1 года назад |
![]() | CVE-2023-5539 A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. | CVSS3: 4.7 | 2% Низкий | больше 1 года назад |
CVE-2023-5539 A remote code execution risk was identified in the Lesson activity. By ... | CVSS3: 4.7 | 2% Низкий | больше 1 года назад | |
![]() | CVE-2023-30944 The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database. | CVSS3: 5.6 | 1% Низкий | около 2 лет назад |
![]() | CVE-2023-30944 The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database. | CVSS3: 5.6 | 1% Низкий | около 2 лет назад |
CVE-2023-30944 The vulnerability was found Moodle which exists due to insufficient sa ... | CVSS3: 5.6 | 1% Низкий | около 2 лет назад | |
![]() | CVE-2023-30943 The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system. | CVSS3: 6.5 | 18% Средний | около 2 лет назад |
![]() | CVE-2023-30943 The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system. | CVSS3: 6.5 | 18% Средний | около 2 лет назад |
CVE-2023-30943 The vulnerability was found Moodle which exists because the applicatio ... | CVSS3: 6.5 | 18% Средний | около 2 лет назад | |
![]() | CVE-2022-45152 A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks. | CVSS3: 9.1 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2022-45152 A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks. | CVSS3: 9.1 | 0% Низкий | больше 2 лет назад |
CVE-2022-45152 A blind Server-Side Request Forgery (SSRF) vulnerability was found in ... | CVSS3: 9.1 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2022-40316 The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2022-40316 The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
CVE-2022-40316 The H5P activity attempts report did not filter by groups, which in se ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2022-40315 A limited SQL injection risk was identified in the "browse list of users" site administration page. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу