Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

github логотип

GHSA-62wv-866c-rh86

около 3 лет назад

Moodle does not properly restrict comment capabilities

EPSS: Низкий
github логотип

GHSA-62wh-m4jr-233r

почти 3 года назад

Moodle LTI module reflected XSS risk

CVSS3: 6.1
EPSS: Высокий
github логотип

GHSA-625r-4rf7-g699

почти 3 года назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-622h-cjgg-5mx6

около 3 лет назад

Moodle allows attackers to bypass file-management restrictions

EPSS: Низкий
github логотип

GHSA-5xqf-3mwv-q7gm

около 3 лет назад

Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-5xp2-rv4h-mm2q

около 3 лет назад

Moodle Open Redirect Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-5x33-h32w-6vr2

около 4 лет назад

Cross site-scripting (XSS) moodle

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-5wjh-v7c8-wrhx

больше 3 лет назад

Moodle stored Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-5wg9-5w3f-hxmh

около 3 лет назад

Moodle Users could elevate their role when accessing the LTI tool on a provider site

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-5w4h-xrr5-7273

около 3 лет назад

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5rr5-fxhc-jv64

около 3 лет назад

Moodle allows attackers to modify the visibility of a badge

EPSS: Низкий
github логотип

GHSA-5p2x-8427-9fgp

больше 1 года назад

Moodle Improper Access Control vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5jph-mvfm-r27p

около 3 лет назад

Moodle cross-site request forgery (CSRF) vulnerability

EPSS: Низкий
github логотип

GHSA-5hc2-8542-698w

около 3 лет назад

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-5h49-4p8x-9pc2

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitrary web script or HTML via (1) the choose parameter in files/index.php and (2) the sub parameter in doc/index.php.

EPSS: Низкий
github логотип

GHSA-5fgv-cvr8-xg48

около 3 лет назад

Moodle vulnerable to Cross-site Scripting

EPSS: Низкий
github логотип

GHSA-59w4-qq7r-6mf4

около 3 лет назад

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

EPSS: Низкий
github логотип

GHSA-59j6-8g7w-prf7

около 3 лет назад

Moodle exposes hidden grades to students

EPSS: Низкий
github логотип

GHSA-595j-wpfg-23w4

около 3 лет назад

Moodle XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-594q-rvf2-x42j

около 3 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-62wv-866c-rh86

Moodle does not properly restrict comment capabilities

1%
Низкий
около 3 лет назад
github логотип
GHSA-62wh-m4jr-233r

Moodle LTI module reflected XSS risk

CVSS3: 6.1
73%
Высокий
почти 3 года назад
github логотип
GHSA-625r-4rf7-g699

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

CVSS3: 7.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-622h-cjgg-5mx6

Moodle allows attackers to bypass file-management restrictions

0%
Низкий
около 3 лет назад
github логотип
GHSA-5xqf-3mwv-q7gm

Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-5xp2-rv4h-mm2q

Moodle Open Redirect Vulnerability

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-5x33-h32w-6vr2

Cross site-scripting (XSS) moodle

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-5wjh-v7c8-wrhx

Moodle stored Cross-site Scripting

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-5wg9-5w3f-hxmh

Moodle Users could elevate their role when accessing the LTI tool on a provider site

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-5w4h-xrr5-7273

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-5rr5-fxhc-jv64

Moodle allows attackers to modify the visibility of a badge

0%
Низкий
около 3 лет назад
github логотип
GHSA-5p2x-8427-9fgp

Moodle Improper Access Control vulnerability

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-5jph-mvfm-r27p

Moodle cross-site request forgery (CSRF) vulnerability

0%
Низкий
около 3 лет назад
github логотип
GHSA-5hc2-8542-698w

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-5h49-4p8x-9pc2

Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitrary web script or HTML via (1) the choose parameter in files/index.php and (2) the sub parameter in doc/index.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-5fgv-cvr8-xg48

Moodle vulnerable to Cross-site Scripting

0%
Низкий
около 3 лет назад
github логотип
GHSA-59w4-qq7r-6mf4

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

0%
Низкий
около 3 лет назад
github логотип
GHSA-59j6-8g7w-prf7

Moodle exposes hidden grades to students

0%
Низкий
около 3 лет назад
github логотип
GHSA-595j-wpfg-23w4

Moodle XSS Vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-594q-rvf2-x42j

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу