Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2022-40315

больше 2 лет назад

A limited SQL injection risk was identified in the "browse list of users" site administration page.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-40315

больше 2 лет назад

A limited SQL injection risk was identified in the "browse list of use ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-40313

больше 2 лет назад

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2022-40313

больше 2 лет назад

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-40313

больше 2 лет назад

Recursive rendering of Mustache template helpers containing user input ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2022-0983

около 3 лет назад

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-0983

около 3 лет назад

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-0983

около 3 лет назад

An SQL injection risk was identified in Badges code relating to config ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2021-43560

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-43560

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-43560

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-43559

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-43559

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-43559

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2021-43558

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-43558

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-43558

больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2013-7341

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-7341

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-7341

около 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flas ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-40315

A limited SQL injection risk was identified in the "browse list of users" site administration page.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-40315

A limited SQL injection risk was identified in the "browse list of use ...

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-40313

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-40313

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-40313

Recursive rendering of Mustache template helpers containing user input ...

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to config ...

CVSS3: 8.8
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-43559

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-43559

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-43559

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-43558

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-43558

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-43558

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2013-7341

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2013-7341

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2013-7341

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flas ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад

Уязвимостей на страницу