Количество 2 470
Количество 2 470
GHSA-fmfx-pgpf-66r5
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
GHSA-fm6m-fg23-67jq
Moodle Cross-site Scripting vulnerability
GHSA-fjq9-452g-jg3q
moodle: Some users can delete audiences of other reports
GHSA-fj6p-g234-rrv3
Exposure of Sensitive Information in moodle
GHSA-fhgh-fjh9-vq62
Moodle allows remote authenticated users to cause a denial of service (invalid database records)
GHSA-fhg2-r2h9-h7q8
Moodle IDOR when deleting OAuth2 linked accounts
GHSA-ffr2-q8c8-w5xj
login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.
GHSA-fcqv-w7xc-5vmc
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
GHSA-fcpw-vqh5-6qwj
Moodle reflected XSS Vulnerability
GHSA-fccf-p8fx-vjj4
Moodle vulnerable to PHP object injection attacks
GHSA-fc5p-vj3h-x7g4
Moodle allows attackers to obtain sensitive information
GHSA-f9m9-494r-w36p
Moodle allows bypass of intended access restrictions
GHSA-f7qm-q26p-6rr2
Moodle cross-site scripting (XSS) vulnerability
GHSA-f6mh-79vh-2hv7
Cross-site Scripting in Moodle Chat
GHSA-f6hv-6fvm-7xr9
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
GHSA-f66h-6mj2-rwj2
Moodle multiple cross-site scripting (XSS) vulnerabilities
GHSA-f5r8-7h4f-jr9x
Moodle incorrect access control
GHSA-f5pm-c4cw-563p
Moodle cross-site request forgery (CSRF) vulnerability
GHSA-f46j-r7q3-6cm2
Moodle SQL Injection vulnerability
GHSA-cxp8-jjf5-6whc
Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-fmfx-pgpf-66r5 Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text. | 0% Низкий | около 3 лет назад | ||
GHSA-fm6m-fg23-67jq Moodle Cross-site Scripting vulnerability | CVSS3: 5.4 | 0% Низкий | почти 3 года назад | |
GHSA-fjq9-452g-jg3q moodle: Some users can delete audiences of other reports | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
GHSA-fj6p-g234-rrv3 Exposure of Sensitive Information in moodle | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-fhgh-fjh9-vq62 Moodle allows remote authenticated users to cause a denial of service (invalid database records) | 1% Низкий | около 3 лет назад | ||
GHSA-fhg2-r2h9-h7q8 Moodle IDOR when deleting OAuth2 linked accounts | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
GHSA-ffr2-q8c8-w5xj login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network. | 0% Низкий | около 3 лет назад | ||
GHSA-fcqv-w7xc-5vmc Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-fcpw-vqh5-6qwj Moodle reflected XSS Vulnerability | CVSS3: 6.1 | 1% Низкий | почти 3 года назад | |
GHSA-fccf-p8fx-vjj4 Moodle vulnerable to PHP object injection attacks | 2% Низкий | около 3 лет назад | ||
GHSA-fc5p-vj3h-x7g4 Moodle allows attackers to obtain sensitive information | 0% Низкий | около 3 лет назад | ||
GHSA-f9m9-494r-w36p Moodle allows bypass of intended access restrictions | 0% Низкий | около 3 лет назад | ||
GHSA-f7qm-q26p-6rr2 Moodle cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-f6mh-79vh-2hv7 Cross-site Scripting in Moodle Chat | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-f6hv-6fvm-7xr9 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search. | 0% Низкий | около 3 лет назад | ||
GHSA-f66h-6mj2-rwj2 Moodle multiple cross-site scripting (XSS) vulnerabilities | 0% Низкий | около 3 лет назад | ||
GHSA-f5r8-7h4f-jr9x Moodle incorrect access control | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-f5pm-c4cw-563p Moodle cross-site request forgery (CSRF) vulnerability | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-f46j-r7q3-6cm2 Moodle SQL Injection vulnerability | CVSS3: 9.8 | 26% Средний | больше 2 лет назад | |
GHSA-cxp8-jjf5-6whc Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу