Количество 2 712
Количество 2 712
GHSA-h6px-pvfh-q2jv
Moodle vulnerable to Cross-Site Scripting
GHSA-h697-w4ph-7pcx
Moodle has a stored XSS in ddimageortext question type
GHSA-h58j-h7qq-f2c2
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.
GHSA-h46g-v2m5-f7jh
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.
GHSA-h34c-px28-rjgw
Moodle mishandles group-based authorization checks
GHSA-h2rg-p9qr-pqcr
course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.
GHSA-gxf9-5xr3-34cc
Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.
GHSA-gwf6-q6c2-94p3
Moodle ReCAPTCHA can be bypassed on the login page
GHSA-gw95-48xq-gqf9
Moodle sensitive information disclosure
GHSA-gw89-x73p-wccw
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.
GHSA-gv8f-43pg-c5qw
Moodle Improper Input Validation vulnerability
GHSA-grvw-qq2j-r898
Moodle multiple cross-site scripting (XSS) vulnerabilities
GHSA-grmj-gpwm-98ww
Moodle Cross-site Scripting vulnerability
GHSA-grj4-g57c-9xmv
Moodle Bypass email verification secret when confirming account registration
GHSA-gr8w-hm62-xw58
Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.
GHSA-gr8j-qm8r-rfgg
Moodle Improper Access Control
GHSA-gr5q-9q5x-fx8h
SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
GHSA-gqrp-qhv8-phrv
Moodle Cross-site Scripting
GHSA-gq9f-8rj4-w7jc
Moodle CSRF risk in admin preset tool management of presets
GHSA-gphj-63h8-r9vq
Moodle directory traversal vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-h6px-pvfh-q2jv Moodle vulnerable to Cross-Site Scripting | 1% Низкий | около 4 лет назад | ||
GHSA-h697-w4ph-7pcx Moodle has a stored XSS in ddimageortext question type | CVSS3: 3.4 | 0% Низкий | больше 1 года назад | |
GHSA-h58j-h7qq-f2c2 The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device. | 0% Низкий | около 4 лет назад | ||
GHSA-h46g-v2m5-f7jh mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document. | 1% Низкий | около 4 лет назад | ||
GHSA-h34c-px28-rjgw Moodle mishandles group-based authorization checks | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-h2rg-p9qr-pqcr course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request. | 1% Низкий | около 4 лет назад | ||
GHSA-gxf9-5xr3-34cc Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string. | 1% Низкий | около 4 лет назад | ||
GHSA-gwf6-q6c2-94p3 Moodle ReCAPTCHA can be bypassed on the login page | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-gw95-48xq-gqf9 Moodle sensitive information disclosure | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-gw89-x73p-wccw webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service. | 1% Низкий | около 4 лет назад | ||
GHSA-gv8f-43pg-c5qw Moodle Improper Input Validation vulnerability | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-grvw-qq2j-r898 Moodle multiple cross-site scripting (XSS) vulnerabilities | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-grmj-gpwm-98ww Moodle Cross-site Scripting vulnerability | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-grj4-g57c-9xmv Moodle Bypass email verification secret when confirming account registration | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-gr8w-hm62-xw58 Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365. | 1% Низкий | около 4 лет назад | ||
GHSA-gr8j-qm8r-rfgg Moodle Improper Access Control | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-gr5q-9q5x-fx8h SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event. | 1% Низкий | около 4 лет назад | ||
GHSA-gqrp-qhv8-phrv Moodle Cross-site Scripting | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-gq9f-8rj4-w7jc Moodle CSRF risk in admin preset tool management of presets | CVSS3: 8.4 | 0% Низкий | около 2 лет назад | |
GHSA-gphj-63h8-r9vq Moodle directory traversal vulnerability | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу