Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

github логотип

GHSA-6r76-f8c8-fh7p

около 3 лет назад

Moodle Cross-site Scripting in assignment submission page

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6q9g-3vfq-q2qj

около 3 лет назад

Improper Authentication in moodle

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6q96-wmxp-mc79

около 3 лет назад

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

EPSS: Низкий
github логотип

GHSA-6p3g-hw27-qh44

около 3 лет назад

Moodle's time-validation implementation allows bypassing intended restrictions

EPSS: Низкий
github логотип

GHSA-6mxm-wpqv-675h

около 3 лет назад

Moodle XSS from profile fields from external db

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6jjc-cvfw-6mr6

около 3 лет назад

help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

EPSS: Низкий
github логотип

GHSA-6jhm-4vmx-mr76

больше 3 лет назад

SQL injection in Moodle

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-6gx2-g773-hv9h

больше 2 лет назад

Moodle reflected cross-site scripting vulnerability in policy tool

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6ggr-h9vf-pg47

около 3 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

EPSS: Низкий
github логотип

GHSA-69xm-pcg8-8qxm

около 3 лет назад

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-69c3-5xxf-58q2

около 3 лет назад

SQL injection in moodle

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-6922-5v25-p8jg

около 3 лет назад

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-68x5-4jg5-gjgg

около 1 года назад

Moodle CSRF risk in analytics management of models

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-68fm-qg53-rwwj

около 3 лет назад

SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int.

EPSS: Низкий
github логотип

GHSA-688p-pgj4-77hh

около 3 лет назад

Moodle allows attackers to obtain sensitive course-structure information

EPSS: Низкий
github логотип

GHSA-683c-cq88-f22q

около 3 лет назад

** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-66xp-28cq-mrf2

около 3 лет назад

Moodle Denial of Service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6656-6qwx-4c2m

около 3 лет назад

Moodle XSS In Tag Autocomplete functionality

EPSS: Низкий
github логотип

GHSA-664q-mrxx-2x2v

около 3 лет назад

Moodle does not properly manage privileges for WebDAV repositories

EPSS: Низкий
github логотип

GHSA-659w-gh8v-v435

около 3 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6r76-f8c8-fh7p

Moodle Cross-site Scripting in assignment submission page

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-6q9g-3vfq-q2qj

Improper Authentication in moodle

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-6q96-wmxp-mc79

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

0%
Низкий
около 3 лет назад
github логотип
GHSA-6p3g-hw27-qh44

Moodle's time-validation implementation allows bypassing intended restrictions

0%
Низкий
около 3 лет назад
github логотип
GHSA-6mxm-wpqv-675h

Moodle XSS from profile fields from external db

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-6jjc-cvfw-6mr6

help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

0%
Низкий
около 3 лет назад
github логотип
GHSA-6jhm-4vmx-mr76

SQL injection in Moodle

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-6gx2-g773-hv9h

Moodle reflected cross-site scripting vulnerability in policy tool

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-6ggr-h9vf-pg47

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

0%
Низкий
около 3 лет назад
github логотип
GHSA-69xm-pcg8-8qxm

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-69c3-5xxf-58q2

SQL injection in moodle

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-6922-5v25-p8jg

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-68x5-4jg5-gjgg

Moodle CSRF risk in analytics management of models

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-68fm-qg53-rwwj

SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int.

2%
Низкий
около 3 лет назад
github логотип
GHSA-688p-pgj4-77hh

Moodle allows attackers to obtain sensitive course-structure information

0%
Низкий
около 3 лет назад
github логотип
GHSA-683c-cq88-f22q

** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-66xp-28cq-mrf2

Moodle Denial of Service

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-6656-6qwx-4c2m

Moodle XSS In Tag Autocomplete functionality

0%
Низкий
около 3 лет назад
github логотип
GHSA-664q-mrxx-2x2v

Moodle does not properly manage privileges for WebDAV repositories

1%
Низкий
около 3 лет назад
github логотип
GHSA-659w-gh8v-v435

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу