Количество 2 470
Количество 2 470
GHSA-6r76-f8c8-fh7p
Moodle Cross-site Scripting in assignment submission page
GHSA-6q9g-3vfq-q2qj
Improper Authentication in moodle
GHSA-6q96-wmxp-mc79
backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.
GHSA-6p3g-hw27-qh44
Moodle's time-validation implementation allows bypassing intended restrictions
GHSA-6mxm-wpqv-675h
Moodle XSS from profile fields from external db
GHSA-6jjc-cvfw-6mr6
help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.
GHSA-6jhm-4vmx-mr76
SQL injection in Moodle
GHSA-6gx2-g773-hv9h
Moodle reflected cross-site scripting vulnerability in policy tool
GHSA-6ggr-h9vf-pg47
mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.
GHSA-69xm-pcg8-8qxm
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
GHSA-69c3-5xxf-58q2
SQL injection in moodle
GHSA-6922-5v25-p8jg
Moodle multiple cross-site scripting (XSS) vulnerabilities
GHSA-68x5-4jg5-gjgg
Moodle CSRF risk in analytics management of models
GHSA-68fm-qg53-rwwj
SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int.
GHSA-688p-pgj4-77hh
Moodle allows attackers to obtain sensitive course-structure information
GHSA-683c-cq88-f22q
** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."
GHSA-66xp-28cq-mrf2
Moodle Denial of Service
GHSA-6656-6qwx-4c2m
Moodle XSS In Tag Autocomplete functionality
GHSA-664q-mrxx-2x2v
Moodle does not properly manage privileges for WebDAV repositories
GHSA-659w-gh8v-v435
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-6r76-f8c8-fh7p Moodle Cross-site Scripting in assignment submission page | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-6q9g-3vfq-q2qj Improper Authentication in moodle | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-6q96-wmxp-mc79 backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action. | 0% Низкий | около 3 лет назад | ||
GHSA-6p3g-hw27-qh44 Moodle's time-validation implementation allows bypassing intended restrictions | 0% Низкий | около 3 лет назад | ||
GHSA-6mxm-wpqv-675h Moodle XSS from profile fields from external db | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-6jjc-cvfw-6mr6 help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message. | 0% Низкий | около 3 лет назад | ||
GHSA-6jhm-4vmx-mr76 SQL injection in Moodle | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад | |
GHSA-6gx2-g773-hv9h Moodle reflected cross-site scripting vulnerability in policy tool | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-6ggr-h9vf-pg47 mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time. | 0% Низкий | около 3 лет назад | ||
GHSA-69xm-pcg8-8qxm In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-69c3-5xxf-58q2 SQL injection in moodle | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-6922-5v25-p8jg Moodle multiple cross-site scripting (XSS) vulnerabilities | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-68x5-4jg5-gjgg Moodle CSRF risk in analytics management of models | CVSS3: 8.8 | 0% Низкий | около 1 года назад | |
GHSA-68fm-qg53-rwwj SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int. | 2% Низкий | около 3 лет назад | ||
GHSA-688p-pgj4-77hh Moodle allows attackers to obtain sensitive course-structure information | 0% Низкий | около 3 лет назад | ||
GHSA-683c-cq88-f22q ** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields." | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-66xp-28cq-mrf2 Moodle Denial of Service | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-6656-6qwx-4c2m Moodle XSS In Tag Autocomplete functionality | 0% Низкий | около 3 лет назад | ||
GHSA-664q-mrxx-2x2v Moodle does not properly manage privileges for WebDAV repositories | 1% Низкий | около 3 лет назад | ||
GHSA-659w-gh8v-v435 lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу