Количество 2 712
Количество 2 712
GHSA-gp4w-f57r-9rx3
Moodle Exposure of Sensitive Information to an Unauthorized Actor
GHSA-gmx9-p92v-48wf
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.
GHSA-gmhr-6f43-7qpj
Moodle does not properly implement group-based access restrictions
GHSA-gj2j-ppjq-9pjg
Moodle Cross-site scripting (XSS) vulnerability in course management search
GHSA-ghqg-3wq5-437q
Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.
GHSA-ggxq-2mg9-8966
Moodle has a Remote Code Execution risk via file restore
GHSA-gfh4-f3wf-9223
Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.
GHSA-gccq-w3xv-4gqh
Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt.
GHSA-g9qp-5vrr-hh2c
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
GHSA-g9m2-c2x5-fr2v
Moodle does not revoke role capabilities correctly
GHSA-g9hp-48jv-xq85
Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.
GHSA-g96h-wvrm-c2ww
Moodle Improper Access Control
GHSA-g8r3-2v89-j6r5
Moodle IDOR when accessing list of badge recipients
GHSA-g88w-v4cq-qgcp
Moodle has an IDOR in badges allows disabling of arbitrary badges
GHSA-g6h6-4fp6-w33w
Moodle vulnerable to Stored Cross-site Scripting
GHSA-g6cp-x8gq-65wc
Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.
GHSA-g632-g52c-3j8c
Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter.
GHSA-g5p6-83fw-2xvf
lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.
GHSA-g5m5-j48g-fr24
Moodle Cross Site Scripting (XSS)
GHSA-g58x-p3pj-rg52
Moodle Glossary search displays entries without checking user permissions to view them
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-gp4w-f57r-9rx3 Moodle Exposure of Sensitive Information to an Unauthorized Actor | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
GHSA-gmx9-p92v-48wf Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks. | 2% Низкий | около 4 лет назад | ||
GHSA-gmhr-6f43-7qpj Moodle does not properly implement group-based access restrictions | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-gj2j-ppjq-9pjg Moodle Cross-site scripting (XSS) vulnerability in course management search | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-ghqg-3wq5-437q Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields. | 1% Низкий | около 4 лет назад | ||
GHSA-ggxq-2mg9-8966 Moodle has a Remote Code Execution risk via file restore | CVSS3: 7.2 | 1% Низкий | 5 месяцев назад | |
GHSA-gfh4-f3wf-9223 Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php. | 1% Низкий | около 4 лет назад | ||
GHSA-gccq-w3xv-4gqh Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via a crafted username that is improperly handled during the logging of an invalid login attempt. | 1% Низкий | около 4 лет назад | ||
GHSA-g9qp-5vrr-hh2c In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-g9m2-c2x5-fr2v Moodle does not revoke role capabilities correctly | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-g9hp-48jv-xq85 Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php. | 1% Низкий | около 4 лет назад | ||
GHSA-g96h-wvrm-c2ww Moodle Improper Access Control | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-g8r3-2v89-j6r5 Moodle IDOR when accessing list of badge recipients | 0% Низкий | больше 1 года назад | ||
GHSA-g88w-v4cq-qgcp Moodle has an IDOR in badges allows disabling of arbitrary badges | CVSS3: 3.1 | 0% Низкий | больше 1 года назад | |
GHSA-g6h6-4fp6-w33w Moodle vulnerable to Stored Cross-site Scripting | CVSS3: 4.8 | 1% Низкий | больше 3 лет назад | |
GHSA-g6cp-x8gq-65wc Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL. | 1% Низкий | около 4 лет назад | ||
GHSA-g632-g52c-3j8c Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) lti_typename or (2) lti_toolurl parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-g5p6-83fw-2xvf lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature. | 1% Низкий | около 4 лет назад | ||
GHSA-g5m5-j48g-fr24 Moodle Cross Site Scripting (XSS) | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-g58x-p3pj-rg52 Moodle Glossary search displays entries without checking user permissions to view them | CVSS3: 5.3 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу