Количество 2 712
Количество 2 712
GHSA-wx87-h539-4775
Moodle Information Disclosure vulnerability
GHSA-wwv7-h477-wrv7
Moodle Stored XSS and blind SSRF possible via SCORM track details
GHSA-wwrq-jww7-39jq
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
GHSA-wwjf-gwrv-wh45
Moodle's IDOR in badges allows deletion of arbitrary badges
GHSA-ww45-x87c-wgff
Moodle all messaging conversations could be viewed
GHSA-wvh5-78h5-gmgr
Cross-site Scripting in moodle
GHSA-wv9c-pfpm-4wc5
Moodle CSRF Vulnerability
GHSA-wr88-x8cm-7cgq
Moodle has a stored XSS risk in admin live log
GHSA-wr6q-xv23-rfq9
Moodle Incorrect Authorization
GHSA-wq3g-p65w-h4pr
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.
GHSA-wpq5-q3mj-8f3r
Moodle multiple cross-site request forgery (CSRF) vulnerabilities
GHSA-wp3g-pr4h-q6vv
Moodle does not enforce capability requirements for reading blog comments
GHSA-wmvq-q9h8-7j4g
Moodle sensitive information disclosure
GHSA-wmmc-qjq2-vvm2
Moodle is vulnerable to Sensitive Information Disclosure
GHSA-wm4w-8vc6-2j4h
Moodle XSS Vulnerability
GHSA-wjh9-wgjp-jmj6
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.
GHSA-wj74-553p-4fv5
mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.
GHSA-wfmm-xq3h-78xx
grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.
GHSA-w979-xjw9-2g82
Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.
GHSA-w77v-xpxr-c6pv
Moodle cross-site scripting (XSS) vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-wx87-h539-4775 Moodle Information Disclosure vulnerability | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-wwv7-h477-wrv7 Moodle Stored XSS and blind SSRF possible via SCORM track details | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-wwrq-jww7-39jq Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs. | 2% Низкий | больше 4 лет назад | ||
GHSA-wwjf-gwrv-wh45 Moodle's IDOR in badges allows deletion of arbitrary badges | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-ww45-x87c-wgff Moodle all messaging conversations could be viewed | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-wvh5-78h5-gmgr Cross-site Scripting in moodle | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-wv9c-pfpm-4wc5 Moodle CSRF Vulnerability | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-wr88-x8cm-7cgq Moodle has a stored XSS risk in admin live log | CVSS3: 8.3 | 0% Низкий | больше 1 года назад | |
GHSA-wr6q-xv23-rfq9 Moodle Incorrect Authorization | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
GHSA-wq3g-p65w-h4pr Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist. | 2% Низкий | около 4 лет назад | ||
GHSA-wpq5-q3mj-8f3r Moodle multiple cross-site request forgery (CSRF) vulnerabilities | 1% Низкий | около 4 лет назад | ||
GHSA-wp3g-pr4h-q6vv Moodle does not enforce capability requirements for reading blog comments | 2% Низкий | около 4 лет назад | ||
GHSA-wmvq-q9h8-7j4g Moodle sensitive information disclosure | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-wmmc-qjq2-vvm2 Moodle is vulnerable to Sensitive Information Disclosure | 2% Низкий | около 4 лет назад | ||
GHSA-wm4w-8vc6-2j4h Moodle XSS Vulnerability | CVSS3: 5.3 | 14% Средний | около 4 лет назад | |
GHSA-wjh9-wgjp-jmj6 report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report. | 1% Низкий | около 4 лет назад | ||
GHSA-wj74-553p-4fv5 mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions. | 1% Низкий | около 4 лет назад | ||
GHSA-wfmm-xq3h-78xx grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature. | 1% Низкий | около 4 лет назад | ||
GHSA-w979-xjw9-2g82 Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups. | 1% Низкий | около 4 лет назад | ||
GHSA-w77v-xpxr-c6pv Moodle cross-site scripting (XSS) vulnerability | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу