Количество 2 712
Количество 2 712
GHSA-c6g7-c2cg-grhj
A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role.
GHSA-c5vq-jr45-v9q2
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
GHSA-c5hf-mc85-2hx4
Missing authorization in Moodle
GHSA-c5cj-xp43-qcc3
Moodle's error handling leads to sensitive information disclosure
GHSA-c4cq-v4wp-28hg
Moodle sensitive information disclosure
GHSA-c3vx-v4x8-x894
Moodle does not check for the moodle/course:viewhiddencourses capability
GHSA-c3pr-h96w-2jjg
Moodle XML import of ddwtos could lead to intentional remote code execution
GHSA-c3j6-33r4-89q3
Moodle Client side denial of service via personal message
GHSA-c2r4-f8qv-2v7v
Moodle allows attackers to read SCORM contents
GHSA-c2gc-3pq9-wq9x
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.
GHSA-9xp2-5fr9-7mwm
Moodle vulnerable to SQL injection
GHSA-9x63-m3cc-qf3g
Moodle Unauthorized searching of arbitrary blogs by typing full url
GHSA-9vc3-vm42-fjhm
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
GHSA-9v64-447r-wch6
Moodle Temporary Passwords are Brute Force-able
GHSA-9v3m-3w47-83fq
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
GHSA-9r7q-rgxm-f2hm
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.
GHSA-9r38-f9p6-3f7p
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
GHSA-9r26-5w88-qhp9
Authorization Bypass in moodle
GHSA-9qm6-cmrx-3j39
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.
GHSA-9qgq-93c7-9hm4
Moodle stored Cross-site Scripting (XSS)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-c6g7-c2cg-grhj A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role. | 1% Низкий | около 4 лет назад | ||
GHSA-c5vq-jr45-v9q2 Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions. | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-c5hf-mc85-2hx4 Missing authorization in Moodle | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-c5cj-xp43-qcc3 Moodle's error handling leads to sensitive information disclosure | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад | |
GHSA-c4cq-v4wp-28hg Moodle sensitive information disclosure | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-c3vx-v4x8-x894 Moodle does not check for the moodle/course:viewhiddencourses capability | 2% Низкий | около 4 лет назад | ||
GHSA-c3pr-h96w-2jjg Moodle XML import of ddwtos could lead to intentional remote code execution | CVSS3: 8.8 | 4% Низкий | около 4 лет назад | |
GHSA-c3j6-33r4-89q3 Moodle Client side denial of service via personal message | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-c2r4-f8qv-2v7v Moodle allows attackers to read SCORM contents | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-c2gc-3pq9-wq9x The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request. | 2% Низкий | около 4 лет назад | ||
GHSA-9xp2-5fr9-7mwm Moodle vulnerable to SQL injection | 2% Низкий | около 4 лет назад | ||
GHSA-9x63-m3cc-qf3g Moodle Unauthorized searching of arbitrary blogs by typing full url | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-9vc3-vm42-fjhm Moodle's mod_data edit/delete pages pass CSRF token in GET parameter | CVSS3: 3.1 | 0% Низкий | больше 1 года назад | |
GHSA-9v64-447r-wch6 Moodle Temporary Passwords are Brute Force-able | 2% Низкий | около 4 лет назад | ||
GHSA-9v3m-3w47-83fq blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed. | 1% Низкий | около 4 лет назад | ||
GHSA-9r7q-rgxm-f2hm A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions. | 1% Низкий | около 4 лет назад | ||
GHSA-9r38-f9p6-3f7p rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed. | 1% Низкий | около 4 лет назад | ||
GHSA-9r26-5w88-qhp9 Authorization Bypass in moodle | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
GHSA-9qm6-cmrx-3j39 Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action. | 1% Низкий | около 4 лет назад | ||
GHSA-9qgq-93c7-9hm4 Moodle stored Cross-site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу