Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-g4wf-f588-7xc7

около 4 лет назад

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fwfj-8p36-rc64

около 3 лет назад

Moodle vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-frr2-fxm8-76rw

около 4 лет назад

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

EPSS: Низкий
github логотип

GHSA-frhc-9hwc-x7j3

около 4 лет назад

Moodle allows attackers to obtain sensitive information

EPSS: Низкий
github логотип

GHSA-fr9m-pjmm-qx9f

около 4 лет назад

Moodle allows attackers to obtain sensitive calendar-event information

EPSS: Низкий
github логотип

GHSA-fqrg-vmvj-jv3x

около 4 лет назад

Moodle allows attackers obtain full-name information

EPSS: Низкий
github логотип

GHSA-fq3r-xmqf-p5w7

почти 3 года назад

** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-fp4h-j22r-vwcv

около 4 лет назад

Moodle allows attackers to obtain sensitive course information

EPSS: Низкий
github логотип

GHSA-fmq9-58q4-xjw5

около 4 лет назад

Moodle allows attackers to discover hidden course names

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fmfx-pgpf-66r5

больше 4 лет назад

Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.

EPSS: Низкий
github логотип

GHSA-fm6m-fg23-67jq

почти 4 года назад

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-fjq9-452g-jg3q

больше 1 года назад

moodle: Some users can delete audiences of other reports

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fj6p-g234-rrv3

около 4 лет назад

Exposure of Sensitive Information in moodle

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fhgh-fjh9-vq62

около 4 лет назад

Moodle allows remote authenticated users to cause a denial of service (invalid database records)

EPSS: Низкий
github логотип

GHSA-fhg2-r2h9-h7q8

больше 1 года назад

Moodle IDOR when deleting OAuth2 linked accounts

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-ffr2-q8c8-w5xj

около 4 лет назад

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

EPSS: Низкий
github логотип

GHSA-fcqv-w7xc-5vmc

около 2 лет назад

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-fcpw-vqh5-6qwj

почти 4 года назад

Moodle reflected XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-fccf-p8fx-vjj4

около 4 лет назад

Moodle vulnerable to PHP object injection attacks

EPSS: Низкий
github логотип

GHSA-fc5p-vj3h-x7g4

около 4 лет назад

Moodle allows attackers to obtain sensitive information

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-g4wf-f588-7xc7

mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-fwfj-8p36-rc64

Moodle vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-frr2-fxm8-76rw

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

1%
Низкий
около 4 лет назад
github логотип
GHSA-frhc-9hwc-x7j3

Moodle allows attackers to obtain sensitive information

2%
Низкий
около 4 лет назад
github логотип
GHSA-fr9m-pjmm-qx9f

Moodle allows attackers to obtain sensitive calendar-event information

2%
Низкий
около 4 лет назад
github логотип
GHSA-fqrg-vmvj-jv3x

Moodle allows attackers obtain full-name information

2%
Низкий
около 4 лет назад
github логотип
GHSA-fq3r-xmqf-p5w7

** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-fp4h-j22r-vwcv

Moodle allows attackers to obtain sensitive course information

2%
Низкий
около 4 лет назад
github логотип
GHSA-fmq9-58q4-xjw5

Moodle allows attackers to discover hidden course names

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-fmfx-pgpf-66r5

Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-fm6m-fg23-67jq

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-fjq9-452g-jg3q

moodle: Some users can delete audiences of other reports

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-fj6p-g234-rrv3

Exposure of Sensitive Information in moodle

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-fhgh-fjh9-vq62

Moodle allows remote authenticated users to cause a denial of service (invalid database records)

2%
Низкий
около 4 лет назад
github логотип
GHSA-fhg2-r2h9-h7q8

Moodle IDOR when deleting OAuth2 linked accounts

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-ffr2-q8c8-w5xj

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

2%
Низкий
около 4 лет назад
github логотип
GHSA-fcqv-w7xc-5vmc

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

CVSS3: 5.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-fcpw-vqh5-6qwj

Moodle reflected XSS Vulnerability

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-fccf-p8fx-vjj4

Moodle vulnerable to PHP object injection attacks

4%
Низкий
около 4 лет назад
github логотип
GHSA-fc5p-vj3h-x7g4

Moodle allows attackers to obtain sensitive information

2%
Низкий
около 4 лет назад

Уязвимостей на страницу