Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 713

Количество 2 713

github логотип

GHSA-gp4w-f57r-9rx3

почти 4 года назад

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gmx9-p92v-48wf

больше 4 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

EPSS: Низкий
github логотип

GHSA-gmhr-6f43-7qpj

больше 4 лет назад

Moodle does not properly implement group-based access restrictions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gj2j-ppjq-9pjg

больше 4 лет назад

Moodle Cross-site scripting (XSS) vulnerability in course management search

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-ghqg-3wq5-437q

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

EPSS: Низкий
github логотип

GHSA-ggxq-2mg9-8966

7 месяцев назад

Moodle has a Remote Code Execution risk via file restore

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-gfh4-f3wf-9223

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

EPSS: Низкий
github логотип

GHSA-gccq-w3xv-4gqh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.

EPSS: Низкий
github логотип

GHSA-g9qp-5vrr-hh2c

около 4 лет назад

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g9m2-c2x5-fr2v

больше 4 лет назад

Moodle does not revoke role capabilities correctly

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-g9hp-48jv-xq85

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

EPSS: Низкий
github логотип

GHSA-g96h-wvrm-c2ww

больше 4 лет назад

Moodle Improper Access Control

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g8r3-2v89-j6r5

почти 2 года назад

Moodle IDOR when accessing list of badge recipients

EPSS: Низкий
github логотип

GHSA-g88w-v4cq-qgcp

больше 1 года назад

Moodle has an IDOR in badges allows disabling of arbitrary badges

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-g6h6-4fp6-w33w

больше 3 лет назад

Moodle vulnerable to Stored Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-g6cp-x8gq-65wc

больше 4 лет назад

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

EPSS: Низкий
github логотип

GHSA-g632-g52c-3j8c

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

EPSS: Низкий
github логотип

GHSA-g5p6-83fw-2xvf

больше 4 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

EPSS: Низкий
github логотип

GHSA-g5m5-j48g-fr24

больше 4 лет назад

Moodle Cross Site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-g58x-p3pj-rg52

больше 4 лет назад

Moodle Glossary search displays entries without checking user permissions to view them

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gp4w-f57r-9rx3

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-gmx9-p92v-48wf

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-gmhr-6f43-7qpj

Moodle does not properly implement group-based access restrictions

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-gj2j-ppjq-9pjg

Moodle Cross-site scripting (XSS) vulnerability in course management search

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-ghqg-3wq5-437q

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-ggxq-2mg9-8966

Moodle has a Remote Code Execution risk via file restore

CVSS3: 7.2
1%
Низкий
7 месяцев назад
github логотип
GHSA-gfh4-f3wf-9223

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-gccq-w3xv-4gqh

Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-g9qp-5vrr-hh2c

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-g9m2-c2x5-fr2v

Moodle does not revoke role capabilities correctly

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-g9hp-48jv-xq85

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-g96h-wvrm-c2ww

Moodle Improper Access Control

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-g8r3-2v89-j6r5

Moodle IDOR when accessing list of badge recipients

0%
Низкий
почти 2 года назад
github логотип
GHSA-g88w-v4cq-qgcp

Moodle has an IDOR in badges allows disabling of arbitrary badges

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-g6h6-4fp6-w33w

Moodle vulnerable to Stored Cross-site Scripting

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-g6cp-x8gq-65wc

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-g632-g52c-3j8c

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-g5p6-83fw-2xvf

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-g5m5-j48g-fr24

Moodle Cross Site Scripting (XSS)

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-g58x-p3pj-rg52

Moodle Glossary search displays entries without checking user permissions to view them

CVSS3: 5.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу