Количество 2 712
Количество 2 712
GHSA-cp39-43xr-2wrp
Moodle XSS Vulnerability
GHSA-cm4r-58pj-h2ph
Moodle allows attackers to extract archives to arbitrary directories
GHSA-cjrf-xg77-chpw
Moodle Incorrect sanitation of attributes in forums
GHSA-cj27-r58c-6p6v
Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
GHSA-chmf-m33p-ph8m
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
GHSA-ch68-5r37-p7c3
Moodle cross-site scripting (XSS) vulnerability
GHSA-cgvv-3455-824j
Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter
GHSA-cg8j-5cr2-568q
Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits
GHSA-cfc8-jvc8-5w3f
SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.
GHSA-ccwc-3v75-qp35
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
GHSA-cc94-hwj3-rf65
Moodle's login_as feature leaks information from external repositories
GHSA-c9jp-244j-vh78
Moodle cross-site scripting (XSS) vulnerability
GHSA-c9hq-g4q8-w893
Privilage Escalation in moodle
GHSA-c8v6-vxhf-wcrr
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
GHSA-c8pm-7v2j-xmww
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.
GHSA-c87j-9rrq-h3j8
Moodle allows attackers to trigger the generation of arbitrary messages
GHSA-c7v4-m269-4995
Exposure of Sensitive Information to an Unauthorized Actor in Moodle
GHSA-c7jj-vfmr-j9mj
Moodle command execution vulnerability exists in the default legacy spellchecker plugin
GHSA-c78f-pfch-h9wc
Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.
GHSA-c767-4whh-v7rw
Moodle has user information visibility control issues in gradebook reports
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-cp39-43xr-2wrp Moodle XSS Vulnerability | 3% Низкий | около 4 лет назад | ||
GHSA-cm4r-58pj-h2ph Moodle allows attackers to extract archives to arbitrary directories | 2% Низкий | около 4 лет назад | ||
GHSA-cjrf-xg77-chpw Moodle Incorrect sanitation of attributes in forums | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-cj27-r58c-6p6v Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter. | 1% Низкий | около 4 лет назад | ||
GHSA-chmf-m33p-ph8m Moodle allows IDOR in RSS block, which allows access to additional RSS feeds | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-ch68-5r37-p7c3 Moodle cross-site scripting (XSS) vulnerability | 2% Низкий | около 4 лет назад | ||
GHSA-cgvv-3455-824j Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter | CVSS3: 4.2 | 0% Низкий | около 1 года назад | |
GHSA-cg8j-5cr2-568q Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-cfc8-jvc8-5w3f SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data. | 2% Низкий | около 4 лет назад | ||
GHSA-ccwc-3v75-qp35 Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. | 2% Низкий | больше 4 лет назад | ||
GHSA-cc94-hwj3-rf65 Moodle's login_as feature leaks information from external repositories | 1% Низкий | около 4 лет назад | ||
GHSA-c9jp-244j-vh78 Moodle cross-site scripting (XSS) vulnerability | 5% Низкий | около 4 лет назад | ||
GHSA-c9hq-g4q8-w893 Privilage Escalation in moodle | CVSS3: 5.3 | 1% Низкий | больше 5 лет назад | |
GHSA-c8v6-vxhf-wcrr Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
GHSA-c8pm-7v2j-xmww The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file. | 6% Низкий | около 4 лет назад | ||
GHSA-c87j-9rrq-h3j8 Moodle allows attackers to trigger the generation of arbitrary messages | 2% Низкий | около 4 лет назад | ||
GHSA-c7v4-m269-4995 Exposure of Sensitive Information to an Unauthorized Actor in Moodle | CVSS3: 5.3 | 2% Низкий | почти 5 лет назад | |
GHSA-c7jj-vfmr-j9mj Moodle command execution vulnerability exists in the default legacy spellchecker plugin | CVSS3: 9.1 | 24% Средний | около 4 лет назад | |
GHSA-c78f-pfch-h9wc Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php. | 1% Низкий | около 4 лет назад | ||
GHSA-c767-4whh-v7rw Moodle has user information visibility control issues in gradebook reports | CVSS3: 5.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу