Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-893p-hqf6-mg67

около 4 лет назад

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

EPSS: Низкий
github логотип

GHSA-88xj-97gf-7wpq

больше 1 года назад

Moodle has a CSRF risk in user tours manager that allows tour duplication

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-86v9-gqh9-8268

около 4 лет назад

Moodle vulnerable to Cross-site Scripting

EPSS: Низкий
github логотип

GHSA-853r-xfvj-j429

больше 4 лет назад

SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.

EPSS: Низкий
github логотип

GHSA-7xv5-m4rh-f939

около 4 лет назад

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

EPSS: Низкий
github логотип

GHSA-7x37-gppm-5c5h

около 4 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

EPSS: Низкий
github логотип

GHSA-7wmp-2xmx-g6h8

больше 1 года назад

Moodle authorization headers preserved between "emulated redirects"

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-7w7p-v23v-56qr

около 4 лет назад

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

EPSS: Низкий
github логотип

GHSA-7q33-5wgv-9752

около 4 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

EPSS: Низкий
github логотип

GHSA-7prr-3mfr-r778

около 4 лет назад

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

EPSS: Низкий
github логотип

GHSA-7pjp-fm93-p6pj

больше 2 лет назад

Cross-Site Request Forgery in moodle

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-7p9m-wjgf-7xr6

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

EPSS: Низкий
github логотип

GHSA-7mfw-g8x4-rq2w

около 4 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7h8v-2v8x-h264

больше 5 лет назад

SQL Injection in moodle

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7ghm-fp7p-qvjq

около 4 лет назад

Moodle XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7f5w-xxw9-mqgp

9 месяцев назад

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-7cvw-wrj9-q5fp

около 4 лет назад

Moodle vulnerable to Cross-Site Request Forgery

EPSS: Низкий
github логотип

GHSA-79w6-7hhc-89m9

около 4 лет назад

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

EPSS: Низкий
github логотип

GHSA-79vx-7whj-rvvr

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-79jp-m64f-pgrc

больше 3 лет назад

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-893p-hqf6-mg67

lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

1%
Низкий
около 4 лет назад
github логотип
GHSA-88xj-97gf-7wpq

Moodle has a CSRF risk in user tours manager that allows tour duplication

CVSS3: 3.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-86v9-gqh9-8268

Moodle vulnerable to Cross-site Scripting

2%
Низкий
около 4 лет назад
github логотип
GHSA-853r-xfvj-j429

SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7xv5-m4rh-f939

Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

2%
Низкий
около 4 лет назад
github логотип
GHSA-7x37-gppm-5c5h

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-7wmp-2xmx-g6h8

Moodle authorization headers preserved between "emulated redirects"

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-7w7p-v23v-56qr

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

2%
Низкий
около 4 лет назад
github логотип
GHSA-7q33-5wgv-9752

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7prr-3mfr-r778

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7pjp-fm93-p6pj

Cross-Site Request Forgery in moodle

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-7p9m-wjgf-7xr6

Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.

2%
Низкий
около 4 лет назад
github логотип
GHSA-7mfw-g8x4-rq2w

Moodle XSS Vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-7h8v-2v8x-h264

SQL Injection in moodle

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
github логотип
GHSA-7ghm-fp7p-qvjq

Moodle XSS Vulnerability

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-7f5w-xxw9-mqgp

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-7cvw-wrj9-q5fp

Moodle vulnerable to Cross-Site Request Forgery

1%
Низкий
около 4 лет назад
github логотип
GHSA-79w6-7hhc-89m9

mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

1%
Низкий
около 4 лет назад
github логотип
GHSA-79vx-7whj-rvvr

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-79jp-m64f-pgrc

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу