Количество 2 470
Количество 2 470
GHSA-93gj-rg98-h7mm
Moodle XSS Vulnerability
GHSA-9328-7pcw-vw69
Cross-Site Request Forgery in Moodle
GHSA-92vh-mr2w-j2cr
Moodle Improper Authentication
GHSA-92q5-2h76-vgmj
moodle Improper Access Control
GHSA-8wf8-rc66-c638
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.
GHSA-8vqr-8829-g4x5
lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.
GHSA-8vjj-wf73-w882
Moodle Incorrect Default Settings
GHSA-8v23-w4w5-w83c
Cross-Site Request Forgery in Moodle
GHSA-8rc7-4qfv-4484
Moodle does not properly restrict file access
GHSA-8r7x-qq55-74v2
Moodle does not enforce the forceloginforprofiles setting
GHSA-8qwh-4vwv-7c5m
Moodle Cross-site Scripting (XSS)
GHSA-8p86-57fx-w749
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
GHSA-8p2c-fgqv-ch4v
Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php.
GHSA-8jhp-2gcr-qw96
Moodle vulnerable to RCE via unsafe deserialization
GHSA-8hxm-42v5-66hm
Moodle vulnerable to Cross-Site Request Forgery
GHSA-8gmm-53jc-x5c2
Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.
GHSA-8g5h-gjwq-w5ch
Moodle Logout CSRF in admin/tool/mfa/auth.php
GHSA-8fqh-rfgp-g35q
mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
GHSA-89f3-74m6-g27g
Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module
GHSA-893p-hqf6-mg67
lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-93gj-rg98-h7mm Moodle XSS Vulnerability | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-9328-7pcw-vw69 Cross-Site Request Forgery in Moodle | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-92vh-mr2w-j2cr Moodle Improper Authentication | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-92q5-2h76-vgmj moodle Improper Access Control | CVSS3: 4 | 0% Низкий | около 3 лет назад | |
GHSA-8wf8-rc66-c638 Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed. | 13% Средний | около 3 лет назад | ||
GHSA-8vqr-8829-g4x5 lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors. | 0% Низкий | около 3 лет назад | ||
GHSA-8vjj-wf73-w882 Moodle Incorrect Default Settings | 0% Низкий | около 3 лет назад | ||
GHSA-8v23-w4w5-w83c Cross-Site Request Forgery in Moodle | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-8rc7-4qfv-4484 Moodle does not properly restrict file access | 0% Низкий | около 3 лет назад | ||
GHSA-8r7x-qq55-74v2 Moodle does not enforce the forceloginforprofiles setting | 0% Низкий | около 3 лет назад | ||
GHSA-8qwh-4vwv-7c5m Moodle Cross-site Scripting (XSS) | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-8p86-57fx-w749 Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities. | 0% Низкий | около 3 лет назад | ||
GHSA-8p2c-fgqv-ch4v Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php. | 0% Низкий | около 3 лет назад | ||
GHSA-8jhp-2gcr-qw96 Moodle vulnerable to RCE via unsafe deserialization | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-8hxm-42v5-66hm Moodle vulnerable to Cross-Site Request Forgery | 0% Низкий | около 3 лет назад | ||
GHSA-8gmm-53jc-x5c2 Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message. | 0% Низкий | около 3 лет назад | ||
GHSA-8g5h-gjwq-w5ch Moodle Logout CSRF in admin/tool/mfa/auth.php | 0% Низкий | около 1 года назад | ||
GHSA-8fqh-rfgp-g35q mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors. | 0% Низкий | около 3 лет назад | ||
GHSA-89f3-74m6-g27g Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module | 0% Низкий | около 3 лет назад | ||
GHSA-893p-hqf6-mg67 lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу