Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 713

Количество 2 713

github логотип

GHSA-h6px-pvfh-q2jv

больше 4 лет назад

Moodle vulnerable to Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-h697-w4ph-7pcx

больше 1 года назад

Moodle has a stored XSS in ddimageortext question type

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-h58j-h7qq-f2c2

больше 4 лет назад

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

EPSS: Низкий
github логотип

GHSA-h46g-v2m5-f7jh

больше 4 лет назад

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

EPSS: Низкий
github логотип

GHSA-h34c-px28-rjgw

больше 4 лет назад

Moodle mishandles group-based authorization checks

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-h2rg-p9qr-pqcr

больше 4 лет назад

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

EPSS: Низкий
github логотип

GHSA-gxf9-5xr3-34cc

больше 4 лет назад

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

EPSS: Низкий
github логотип

GHSA-gwf6-q6c2-94p3

больше 2 лет назад

Moodle ReCAPTCHA can be bypassed on the login page

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gw95-48xq-gqf9

больше 4 лет назад

Moodle sensitive information disclosure

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gw89-x73p-wccw

больше 4 лет назад

webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

EPSS: Низкий
github логотип

GHSA-gv8f-43pg-c5qw

больше 3 лет назад

Moodle Improper Input Validation vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-grvw-qq2j-r898

больше 4 лет назад

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-grmj-gpwm-98ww

больше 3 лет назад

Moodle Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-grj4-g57c-9xmv

больше 4 лет назад

Moodle Bypass email verification secret when confirming account registration

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-gr8w-hm62-xw58

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

EPSS: Низкий
github логотип

GHSA-gr8j-qm8r-rfgg

больше 4 лет назад

Moodle Improper Access Control

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gr5q-9q5x-fx8h

больше 4 лет назад

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

EPSS: Низкий
github логотип

GHSA-gqrp-qhv8-phrv

больше 4 лет назад

Moodle Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-gq9f-8rj4-w7jc

больше 2 лет назад

Moodle CSRF risk in admin preset tool management of presets

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-gphj-63h8-r9vq

больше 4 лет назад

Moodle directory traversal vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-h6px-pvfh-q2jv

Moodle vulnerable to Cross-Site Scripting

1%
Низкий
больше 4 лет назад
github логотип
GHSA-h697-w4ph-7pcx

Moodle has a stored XSS in ddimageortext question type

CVSS3: 3.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-h58j-h7qq-f2c2

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-h46g-v2m5-f7jh

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-h34c-px28-rjgw

Moodle mishandles group-based authorization checks

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-h2rg-p9qr-pqcr

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-gxf9-5xr3-34cc

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-gwf6-q6c2-94p3

Moodle ReCAPTCHA can be bypassed on the login page

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-gw95-48xq-gqf9

Moodle sensitive information disclosure

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-gw89-x73p-wccw

webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-gv8f-43pg-c5qw

Moodle Improper Input Validation vulnerability

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-grvw-qq2j-r898

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-grmj-gpwm-98ww

Moodle Cross-site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-grj4-g57c-9xmv

Moodle Bypass email verification secret when confirming account registration

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-gr8w-hm62-xw58

Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-gr8j-qm8r-rfgg

Moodle Improper Access Control

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-gr5q-9q5x-fx8h

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-gqrp-qhv8-phrv

Moodle Cross-site Scripting

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-gq9f-8rj4-w7jc

Moodle CSRF risk in admin preset tool management of presets

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-gphj-63h8-r9vq

Moodle directory traversal vulnerability

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу