Количество 2 712
Количество 2 712
GHSA-g4wf-f588-7xc7
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.
GHSA-fwfj-8p36-rc64
Moodle vulnerable to Cross-site Scripting
GHSA-frr2-fxm8-76rw
The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.
GHSA-frhc-9hwc-x7j3
Moodle allows attackers to obtain sensitive information
GHSA-fr9m-pjmm-qx9f
Moodle allows attackers to obtain sensitive calendar-event information
GHSA-fqrg-vmvj-jv3x
Moodle allows attackers obtain full-name information
GHSA-fq3r-xmqf-p5w7
** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."
GHSA-fp4h-j22r-vwcv
Moodle allows attackers to obtain sensitive course information
GHSA-fmq9-58q4-xjw5
Moodle allows attackers to discover hidden course names
GHSA-fmfx-pgpf-66r5
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
GHSA-fm6m-fg23-67jq
Moodle Cross-site Scripting vulnerability
GHSA-fjq9-452g-jg3q
moodle: Some users can delete audiences of other reports
GHSA-fj6p-g234-rrv3
Exposure of Sensitive Information in moodle
GHSA-fhgh-fjh9-vq62
Moodle allows remote authenticated users to cause a denial of service (invalid database records)
GHSA-fhg2-r2h9-h7q8
Moodle IDOR when deleting OAuth2 linked accounts
GHSA-ffr2-q8c8-w5xj
login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.
GHSA-fcqv-w7xc-5vmc
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
GHSA-fcpw-vqh5-6qwj
Moodle reflected XSS Vulnerability
GHSA-fccf-p8fx-vjj4
Moodle vulnerable to PHP object injection attacks
GHSA-fc5p-vj3h-x7g4
Moodle allows attackers to obtain sensitive information
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-g4wf-f588-7xc7 mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization. | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-fwfj-8p36-rc64 Moodle vulnerable to Cross-site Scripting | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-frr2-fxm8-76rw The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network. | 1% Низкий | около 4 лет назад | ||
GHSA-frhc-9hwc-x7j3 Moodle allows attackers to obtain sensitive information | 2% Низкий | около 4 лет назад | ||
GHSA-fr9m-pjmm-qx9f Moodle allows attackers to obtain sensitive calendar-event information | 2% Низкий | около 4 лет назад | ||
GHSA-fqrg-vmvj-jv3x Moodle allows attackers obtain full-name information | 2% Низкий | около 4 лет назад | ||
GHSA-fq3r-xmqf-p5w7 ** DISPUTED ** Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not." | CVSS3: 5.4 | 1% Низкий | почти 3 года назад | |
GHSA-fp4h-j22r-vwcv Moodle allows attackers to obtain sensitive course information | 2% Низкий | около 4 лет назад | ||
GHSA-fmq9-58q4-xjw5 Moodle allows attackers to discover hidden course names | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-fmfx-pgpf-66r5 Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text. | 1% Низкий | больше 4 лет назад | ||
GHSA-fm6m-fg23-67jq Moodle Cross-site Scripting vulnerability | CVSS3: 5.4 | 1% Низкий | почти 4 года назад | |
GHSA-fjq9-452g-jg3q moodle: Some users can delete audiences of other reports | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-fj6p-g234-rrv3 Exposure of Sensitive Information in moodle | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-fhgh-fjh9-vq62 Moodle allows remote authenticated users to cause a denial of service (invalid database records) | 2% Низкий | около 4 лет назад | ||
GHSA-fhg2-r2h9-h7q8 Moodle IDOR when deleting OAuth2 linked accounts | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-ffr2-q8c8-w5xj login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network. | 2% Низкий | около 4 лет назад | ||
GHSA-fcqv-w7xc-5vmc Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity. | CVSS3: 5.5 | 1% Низкий | около 2 лет назад | |
GHSA-fcpw-vqh5-6qwj Moodle reflected XSS Vulnerability | CVSS3: 6.1 | 1% Низкий | почти 4 года назад | |
GHSA-fccf-p8fx-vjj4 Moodle vulnerable to PHP object injection attacks | 4% Низкий | около 4 лет назад | ||
GHSA-fc5p-vj3h-x7g4 Moodle allows attackers to obtain sensitive information | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу