Количество 2 712
Количество 2 712
GHSA-f9m9-494r-w36p
Moodle allows bypass of intended access restrictions
GHSA-f7qm-q26p-6rr2
Moodle cross-site scripting (XSS) vulnerability
GHSA-f6mh-79vh-2hv7
Cross-site Scripting in Moodle Chat
GHSA-f6hv-6fvm-7xr9
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
GHSA-f66h-6mj2-rwj2
Moodle multiple cross-site scripting (XSS) vulnerabilities
GHSA-f5r8-7h4f-jr9x
Moodle incorrect access control
GHSA-f5pm-c4cw-563p
Moodle cross-site request forgery (CSRF) vulnerability
GHSA-f46j-r7q3-6cm2
Moodle SQL Injection vulnerability
GHSA-f439-48pp-hm2q
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
GHSA-cxp8-jjf5-6whc
Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.
GHSA-cx8w-wqgc-mpmh
Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.
GHSA-cwhp-rqfr-8462
Moodle XSS Vulnerability
GHSA-cw72-69wq-f9f2
Moodle External function mod_assign_save_submission does not check due dates
GHSA-cw24-f6fq-7j9v
Moodle allows teachers to evade trusttext config when restoring glossary entries
GHSA-crcq-pw8h-9xwf
Moodle does not provide charset information in HTTP headers
GHSA-cr78-rphw-w73p
Moodle Arbitrary File Read via Backup Functionality
GHSA-cq5f-wv7p-5gfc
Moodle leaks user names
GHSA-cpp3-82c5-xhqm
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.
GHSA-cpm7-mv33-jwf8
Moodle's AJAX section delete does not respect course_can_delete_section()
GHSA-cp8m-h777-g4p3
Improper Access Control in moodle
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-f9m9-494r-w36p Moodle allows bypass of intended access restrictions | 1% Низкий | около 4 лет назад | ||
GHSA-f7qm-q26p-6rr2 Moodle cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-f6mh-79vh-2hv7 Cross-site Scripting in Moodle Chat | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
GHSA-f6hv-6fvm-7xr9 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search. | 1% Низкий | около 4 лет назад | ||
GHSA-f66h-6mj2-rwj2 Moodle multiple cross-site scripting (XSS) vulnerabilities | 2% Низкий | около 4 лет назад | ||
GHSA-f5r8-7h4f-jr9x Moodle incorrect access control | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-f5pm-c4cw-563p Moodle cross-site request forgery (CSRF) vulnerability | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-f46j-r7q3-6cm2 Moodle SQL Injection vulnerability | CVSS3: 9.8 | 52% Средний | больше 3 лет назад | |
GHSA-f439-48pp-hm2q Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-cxp8-jjf5-6whc Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question. | 1% Низкий | около 4 лет назад | ||
GHSA-cx8w-wqgc-mpmh Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository. | 1% Низкий | около 4 лет назад | ||
GHSA-cwhp-rqfr-8462 Moodle XSS Vulnerability | CVSS3: 5.4 | 1% Низкий | почти 4 года назад | |
GHSA-cw72-69wq-f9f2 Moodle External function mod_assign_save_submission does not check due dates | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-cw24-f6fq-7j9v Moodle allows teachers to evade trusttext config when restoring glossary entries | CVSS3: 3.1 | 0% Низкий | больше 1 года назад | |
GHSA-crcq-pw8h-9xwf Moodle does not provide charset information in HTTP headers | 2% Низкий | около 4 лет назад | ||
GHSA-cr78-rphw-w73p Moodle Arbitrary File Read via Backup Functionality | 1% Низкий | около 4 лет назад | ||
GHSA-cq5f-wv7p-5gfc Moodle leaks user names | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-cpp3-82c5-xhqm Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/. | 3% Низкий | около 4 лет назад | ||
GHSA-cpm7-mv33-jwf8 Moodle's AJAX section delete does not respect course_can_delete_section() | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-cp8m-h777-g4p3 Improper Access Control in moodle | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу