Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 713

Количество 2 713

github логотип

GHSA-c6g7-c2cg-grhj

больше 4 лет назад

A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role.

EPSS: Низкий
github логотип

GHSA-c5vq-jr45-v9q2

больше 4 лет назад

Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c5hf-mc85-2hx4

больше 4 лет назад

Missing authorization in Moodle

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c5cj-xp43-qcc3

11 месяцев назад

Moodle's error handling leads to sensitive information disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c4cq-v4wp-28hg

больше 4 лет назад

Moodle sensitive information disclosure

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-c3vx-v4x8-x894

больше 4 лет назад

Moodle does not check for the moodle/course:viewhiddencourses capability

EPSS: Низкий
github логотип

GHSA-c3pr-h96w-2jjg

больше 4 лет назад

Moodle XML import of ddwtos could lead to intentional remote code execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-c3j6-33r4-89q3

больше 4 лет назад

Moodle Client side denial of service via personal message

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-c2r4-f8qv-2v7v

больше 4 лет назад

Moodle allows attackers to read SCORM contents

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c2gc-3pq9-wq9x

больше 4 лет назад

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

EPSS: Низкий
github логотип

GHSA-9xp2-5fr9-7mwm

больше 4 лет назад

Moodle vulnerable to SQL injection

EPSS: Низкий
github логотип

GHSA-9x63-m3cc-qf3g

больше 4 лет назад

Moodle Unauthorized searching of arbitrary blogs by typing full url

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9vc3-vm42-fjhm

больше 1 года назад

Moodle's mod_data edit/delete pages pass CSRF token in GET parameter

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-9v64-447r-wch6

больше 4 лет назад

Moodle Temporary Passwords are Brute Force-able

EPSS: Низкий
github логотип

GHSA-9v3m-3w47-83fq

больше 4 лет назад

blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.

EPSS: Низкий
github логотип

GHSA-9r7q-rgxm-f2hm

больше 4 лет назад

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

EPSS: Низкий
github логотип

GHSA-9r38-f9p6-3f7p

больше 4 лет назад

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

EPSS: Низкий
github логотип

GHSA-9r26-5w88-qhp9

больше 2 лет назад

Authorization Bypass in moodle

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9qm6-cmrx-3j39

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

EPSS: Низкий
github логотип

GHSA-9qgq-93c7-9hm4

больше 2 лет назад

Moodle stored Cross-site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c6g7-c2cg-grhj

A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be automatically assigned that role.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-c5vq-jr45-v9q2

Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-c5hf-mc85-2hx4

Missing authorization in Moodle

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-c5cj-xp43-qcc3

Moodle's error handling leads to sensitive information disclosure

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-c4cq-v4wp-28hg

Moodle sensitive information disclosure

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-c3vx-v4x8-x894

Moodle does not check for the moodle/course:viewhiddencourses capability

2%
Низкий
больше 4 лет назад
github логотип
GHSA-c3pr-h96w-2jjg

Moodle XML import of ddwtos could lead to intentional remote code execution

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-c3j6-33r4-89q3

Moodle Client side denial of service via personal message

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-c2r4-f8qv-2v7v

Moodle allows attackers to read SCORM contents

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-c2gc-3pq9-wq9x

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-9xp2-5fr9-7mwm

Moodle vulnerable to SQL injection

2%
Низкий
больше 4 лет назад
github логотип
GHSA-9x63-m3cc-qf3g

Moodle Unauthorized searching of arbitrary blogs by typing full url

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-9vc3-vm42-fjhm

Moodle's mod_data edit/delete pages pass CSRF token in GET parameter

CVSS3: 3.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-9v64-447r-wch6

Moodle Temporary Passwords are Brute Force-able

2%
Низкий
больше 4 лет назад
github логотип
GHSA-9v3m-3w47-83fq

blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-9r7q-rgxm-f2hm

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-9r38-f9p6-3f7p

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-9r26-5w88-qhp9

Authorization Bypass in moodle

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-9qm6-cmrx-3j39

Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-9qgq-93c7-9hm4

Moodle stored Cross-site Scripting (XSS)

CVSS3: 6.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу