Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-gp4w-f57r-9rx3

почти 4 года назад

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gmx9-p92v-48wf

около 4 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

EPSS: Низкий
github логотип

GHSA-gmhr-6f43-7qpj

около 4 лет назад

Moodle does not properly implement group-based access restrictions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gj2j-ppjq-9pjg

около 4 лет назад

Moodle Cross-site scripting (XSS) vulnerability in course management search

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-ghqg-3wq5-437q

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

EPSS: Низкий
github логотип

GHSA-ggxq-2mg9-8966

5 месяцев назад

Moodle has a Remote Code Execution risk via file restore

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-gfh4-f3wf-9223

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

EPSS: Низкий
github логотип

GHSA-gccq-w3xv-4gqh

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.

EPSS: Низкий
github логотип

GHSA-g9qp-5vrr-hh2c

почти 4 года назад

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g9m2-c2x5-fr2v

около 4 лет назад

Moodle does not revoke role capabilities correctly

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-g9hp-48jv-xq85

около 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

EPSS: Низкий
github логотип

GHSA-g96h-wvrm-c2ww

около 4 лет назад

Moodle Improper Access Control

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g8r3-2v89-j6r5

больше 1 года назад

Moodle IDOR when accessing list of badge recipients

EPSS: Низкий
github логотип

GHSA-g88w-v4cq-qgcp

больше 1 года назад

Moodle has an IDOR in badges allows disabling of arbitrary badges

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-g6h6-4fp6-w33w

больше 3 лет назад

Moodle vulnerable to Stored Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-g6cp-x8gq-65wc

около 4 лет назад

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

EPSS: Низкий
github логотип

GHSA-g632-g52c-3j8c

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

EPSS: Низкий
github логотип

GHSA-g5p6-83fw-2xvf

около 4 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

EPSS: Низкий
github логотип

GHSA-g5m5-j48g-fr24

около 4 лет назад

Moodle Cross Site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-g58x-p3pj-rg52

около 4 лет назад

Moodle Glossary search displays entries without checking user permissions to view them

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gp4w-f57r-9rx3

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-gmx9-p92v-48wf

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

2%
Низкий
около 4 лет назад
github логотип
GHSA-gmhr-6f43-7qpj

Moodle does not properly implement group-based access restrictions

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-gj2j-ppjq-9pjg

Moodle Cross-site scripting (XSS) vulnerability in course management search

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-ghqg-3wq5-437q

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

1%
Низкий
около 4 лет назад
github логотип
GHSA-ggxq-2mg9-8966

Moodle has a Remote Code Execution risk via file restore

CVSS3: 7.2
1%
Низкий
5 месяцев назад
github логотип
GHSA-gfh4-f3wf-9223

Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-gccq-w3xv-4gqh

Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g9qp-5vrr-hh2c

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-g9m2-c2x5-fr2v

Moodle does not revoke role capabilities correctly

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-g9hp-48jv-xq85

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g96h-wvrm-c2ww

Moodle Improper Access Control

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-g8r3-2v89-j6r5

Moodle IDOR when accessing list of badge recipients

0%
Низкий
больше 1 года назад
github логотип
GHSA-g88w-v4cq-qgcp

Moodle has an IDOR in badges allows disabling of arbitrary badges

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-g6h6-4fp6-w33w

Moodle vulnerable to Stored Cross-site Scripting

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-g6cp-x8gq-65wc

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g632-g52c-3j8c

Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-g5p6-83fw-2xvf

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

1%
Низкий
около 4 лет назад
github логотип
GHSA-g5m5-j48g-fr24

Moodle Cross Site Scripting (XSS)

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-g58x-p3pj-rg52

Moodle Glossary search displays entries without checking user permissions to view them

CVSS3: 5.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу