Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

github логотип

GHSA-cx8w-wqgc-mpmh

около 3 лет назад

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

EPSS: Низкий
github логотип

GHSA-cwhp-rqfr-8462

почти 3 года назад

Moodle XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-cw72-69wq-f9f2

около 3 лет назад

Moodle External function mod_assign_save_submission does not check due dates

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-crcq-pw8h-9xwf

около 3 лет назад

Moodle does not provide charset information in HTTP headers

EPSS: Низкий
github логотип

GHSA-cr78-rphw-w73p

около 3 лет назад

Moodle Arbitrary File Read via Backup Functionality

EPSS: Низкий
github логотип

GHSA-cq5f-wv7p-5gfc

7 месяцев назад

Moodle leaks user names

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cpp3-82c5-xhqm

около 3 лет назад

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

EPSS: Низкий
github логотип

GHSA-cp8m-h777-g4p3

больше 1 года назад

Improper Access Control in moodle

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-cp39-43xr-2wrp

около 3 лет назад

Moodle XSS Vulnerability

EPSS: Низкий
github логотип

GHSA-cm4r-58pj-h2ph

около 3 лет назад

Moodle allows attackers to extract archives to arbitrary directories

EPSS: Низкий
github логотип

GHSA-cjrf-xg77-chpw

около 3 лет назад

Moodle Incorrect sanitation of attributes in forums

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-cj27-r58c-6p6v

около 3 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

EPSS: Низкий
github логотип

GHSA-ch68-5r37-p7c3

около 3 лет назад

Moodle cross-site scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-cfc8-jvc8-5w3f

около 3 лет назад

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

EPSS: Низкий
github логотип

GHSA-ccwc-3v75-qp35

около 3 лет назад

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

EPSS: Низкий
github логотип

GHSA-cc94-hwj3-rf65

около 3 лет назад

Moodle's login_as feature leaks information from external repositories

EPSS: Низкий
github логотип

GHSA-c9jp-244j-vh78

около 3 лет назад

Moodle cross-site scripting (XSS) vulnerability

EPSS: Низкий
github логотип

GHSA-c9hq-g4q8-w893

около 4 лет назад

Privilage Escalation in moodle

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c8pm-7v2j-xmww

около 3 лет назад

The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.

EPSS: Низкий
github логотип

GHSA-c87j-9rrq-h3j8

около 3 лет назад

Moodle allows attackers to trigger the generation of arbitrary messages

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cx8w-wqgc-mpmh

Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

0%
Низкий
около 3 лет назад
github логотип
GHSA-cwhp-rqfr-8462

Moodle XSS Vulnerability

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-cw72-69wq-f9f2

Moodle External function mod_assign_save_submission does not check due dates

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-crcq-pw8h-9xwf

Moodle does not provide charset information in HTTP headers

0%
Низкий
около 3 лет назад
github логотип
GHSA-cr78-rphw-w73p

Moodle Arbitrary File Read via Backup Functionality

0%
Низкий
около 3 лет назад
github логотип
GHSA-cq5f-wv7p-5gfc

Moodle leaks user names

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-cpp3-82c5-xhqm

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

3%
Низкий
около 3 лет назад
github логотип
GHSA-cp8m-h777-g4p3

Improper Access Control in moodle

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-cp39-43xr-2wrp

Moodle XSS Vulnerability

1%
Низкий
около 3 лет назад
github логотип
GHSA-cm4r-58pj-h2ph

Moodle allows attackers to extract archives to arbitrary directories

0%
Низкий
около 3 лет назад
github логотип
GHSA-cjrf-xg77-chpw

Moodle Incorrect sanitation of attributes in forums

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-cj27-r58c-6p6v

Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-ch68-5r37-p7c3

Moodle cross-site scripting (XSS) vulnerability

0%
Низкий
около 3 лет назад
github логотип
GHSA-cfc8-jvc8-5w3f

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

0%
Низкий
около 3 лет назад
github логотип
GHSA-ccwc-3v75-qp35

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

2%
Низкий
около 3 лет назад
github логотип
GHSA-cc94-hwj3-rf65

Moodle's login_as feature leaks information from external repositories

0%
Низкий
около 3 лет назад
github логотип
GHSA-c9jp-244j-vh78

Moodle cross-site scripting (XSS) vulnerability

1%
Низкий
около 3 лет назад
github логотип
GHSA-c9hq-g4q8-w893

Privilage Escalation in moodle

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-c8pm-7v2j-xmww

The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.

6%
Низкий
около 3 лет назад
github логотип
GHSA-c87j-9rrq-h3j8

Moodle allows attackers to trigger the generation of arbitrary messages

0%
Низкий
около 3 лет назад

Уязвимостей на страницу