Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 713

Количество 2 713

github логотип

GHSA-893p-hqf6-mg67

больше 4 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

EPSS: Низкий
github логотип

GHSA-88xj-97gf-7wpq

больше 1 года назад

Moodle has a CSRF risk in user tours manager that allows tour duplication

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-86v9-gqh9-8268

больше 4 лет назад

Moodle vulnerable to Cross-site Scripting

EPSS: Низкий
github логотип

GHSA-853r-xfvj-j429

больше 4 лет назад

SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.

EPSS: Низкий
github логотип

GHSA-7xv5-m4rh-f939

больше 4 лет назад

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

EPSS: Низкий
github логотип

GHSA-7x37-gppm-5c5h

больше 4 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

EPSS: Низкий
github логотип

GHSA-7wmp-2xmx-g6h8

почти 2 года назад

Moodle authorization headers preserved between "emulated redirects"

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7w7p-v23v-56qr

больше 4 лет назад

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

EPSS: Низкий
github логотип

GHSA-7q33-5wgv-9752

больше 4 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

EPSS: Низкий
github логотип

GHSA-7prr-3mfr-r778

больше 4 лет назад

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

EPSS: Низкий
github логотип

GHSA-7pjp-fm93-p6pj

больше 2 лет назад

Cross-Site Request Forgery in moodle

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-7p9m-wjgf-7xr6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

EPSS: Низкий
github логотип

GHSA-7mfw-g8x4-rq2w

больше 4 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7h8v-2v8x-h264

больше 5 лет назад

SQL Injection in moodle

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7ghm-fp7p-qvjq

больше 4 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7f5w-xxw9-mqgp

11 месяцев назад

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7cvw-wrj9-q5fp

больше 4 лет назад

Moodle vulnerable to Cross-Site Request Forgery

EPSS: Низкий
github логотип

GHSA-79w6-7hhc-89m9

больше 4 лет назад

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

EPSS: Низкий
github логотип

GHSA-79vx-7whj-rvvr

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-79jp-m64f-pgrc

больше 3 лет назад

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-893p-hqf6-mg67

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-88xj-97gf-7wpq

Moodle has a CSRF risk in user tours manager that allows tour duplication

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-86v9-gqh9-8268

Moodle vulnerable to Cross-site Scripting

2%
Низкий
больше 4 лет назад
github логотип
GHSA-853r-xfvj-j429

SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7xv5-m4rh-f939

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-7x37-gppm-5c5h

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-7wmp-2xmx-g6h8

Moodle authorization headers preserved between "emulated redirects"

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-7w7p-v23v-56qr

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-7q33-5wgv-9752

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7prr-3mfr-r778

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7pjp-fm93-p6pj

Cross-Site Request Forgery in moodle

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-7p9m-wjgf-7xr6

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-7mfw-g8x4-rq2w

Moodle XSS Vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-7h8v-2v8x-h264

SQL Injection in moodle

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
github логотип
GHSA-7ghm-fp7p-qvjq

Moodle XSS Vulnerability

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-7f5w-xxw9-mqgp

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-7cvw-wrj9-q5fp

Moodle vulnerable to Cross-Site Request Forgery

1%
Низкий
больше 4 лет назад
github логотип
GHSA-79w6-7hhc-89m9

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-79vx-7whj-rvvr

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-79jp-m64f-pgrc

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу