Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

ubuntu логотип

CVE-2022-45152

больше 3 лет назад

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2022-45152

больше 3 лет назад

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2022-45152

больше 3 лет назад

A blind Server-Side Request Forgery (SSRF) vulnerability was found in ...

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2022-40316

почти 4 года назад

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-40316

почти 4 года назад

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-40316

почти 4 года назад

The H5P activity attempts report did not filter by groups, which in se ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-40315

почти 4 года назад

A limited SQL injection risk was identified in the "browse list of users" site administration page.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-40315

почти 4 года назад

A limited SQL injection risk was identified in the "browse list of users" site administration page.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-40315

почти 4 года назад

A limited SQL injection risk was identified in the "browse list of use ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-40313

почти 4 года назад

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2022-40313

почти 4 года назад

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-40313

почти 4 года назад

Recursive rendering of Mustache template helpers containing user input ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2022-0983

больше 4 лет назад

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-0983

больше 4 лет назад

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-0983

больше 4 лет назад

An SQL injection risk was identified in Badges code relating to config ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2021-43560

больше 4 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-43560

больше 4 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-43560

больше 4 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-43559

больше 4 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-43559

больше 4 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-45152

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45152

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45152

A blind Server-Side Request Forgery (SSRF) vulnerability was found in ...

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-40316

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-40316

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-40316

The H5P activity attempts report did not filter by groups, which in se ...

CVSS3: 4.3
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-40315

A limited SQL injection risk was identified in the "browse list of users" site administration page.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-40315

A limited SQL injection risk was identified in the "browse list of users" site administration page.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-40315

A limited SQL injection risk was identified in the "browse list of use ...

CVSS3: 9.8
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-40313

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-40313

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

CVSS3: 7.1
1%
Низкий
почти 4 года назад
debian логотип
CVE-2022-40313

Recursive rendering of Mustache template helpers containing user input ...

CVSS3: 7.1
1%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to config ...

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, ...

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-43559

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-43559

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу