Количество 2 712
Количество 2 712
GHSA-6rm3-82c3-gjr8
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.
GHSA-6rgj-rxh3-3g5j
login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action.
GHSA-6r7x-6q98-qcqp
Moodle does not set the RISK_XSS bit for graders
GHSA-6r76-f8c8-fh7p
Moodle Cross-site Scripting in assignment submission page
GHSA-6q9g-3vfq-q2qj
Improper Authentication in moodle
GHSA-6q96-wmxp-mc79
backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.
GHSA-6p3g-hw27-qh44
Moodle's time-validation implementation allows bypassing intended restrictions
GHSA-6mxm-wpqv-675h
Moodle XSS from profile fields from external db
GHSA-6mmv-f6c6-v6q8
Moodle vulnerable to Cross-site Scripting
GHSA-6jjc-cvfw-6mr6
help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.
GHSA-6jhm-4vmx-mr76
SQL injection in Moodle
GHSA-6gx2-g773-hv9h
Moodle reflected cross-site scripting vulnerability in policy tool
GHSA-6ggr-h9vf-pg47
mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.
GHSA-6g5x-h5x7-q4mq
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
GHSA-69xm-pcg8-8qxm
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
GHSA-69m9-rprc-2x7g
Moodle reveals student identities through assignment submissions search on anonymous submissions
GHSA-69c3-5xxf-58q2
SQL injection in moodle
GHSA-6922-5v25-p8jg
Moodle multiple cross-site scripting (XSS) vulnerabilities
GHSA-68x5-4jg5-gjgg
Moodle CSRF risk in analytics management of models
GHSA-68fm-qg53-rwwj
SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-6rm3-82c3-gjr8 lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role. | 1% Низкий | около 4 лет назад | ||
GHSA-6rgj-rxh3-3g5j login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action. | 1% Низкий | больше 4 лет назад | ||
GHSA-6r7x-6q98-qcqp Moodle does not set the RISK_XSS bit for graders | 1% Низкий | около 4 лет назад | ||
GHSA-6r76-f8c8-fh7p Moodle Cross-site Scripting in assignment submission page | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-6q9g-3vfq-q2qj Improper Authentication in moodle | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-6q96-wmxp-mc79 backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action. | 1% Низкий | около 4 лет назад | ||
GHSA-6p3g-hw27-qh44 Moodle's time-validation implementation allows bypassing intended restrictions | 2% Низкий | около 4 лет назад | ||
GHSA-6mxm-wpqv-675h Moodle XSS from profile fields from external db | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-6mmv-f6c6-v6q8 Moodle vulnerable to Cross-site Scripting | CVSS3: 7.3 | 0% Низкий | 6 месяцев назад | |
GHSA-6jjc-cvfw-6mr6 help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message. | 1% Низкий | больше 4 лет назад | ||
GHSA-6jhm-4vmx-mr76 SQL injection in Moodle | CVSS3: 9.8 | 45% Средний | больше 4 лет назад | |
GHSA-6gx2-g773-hv9h Moodle reflected cross-site scripting vulnerability in policy tool | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-6ggr-h9vf-pg47 mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time. | 1% Низкий | около 4 лет назад | ||
GHSA-6g5x-h5x7-q4mq Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-69xm-pcg8-8qxm In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-69m9-rprc-2x7g Moodle reveals student identities through assignment submissions search on anonymous submissions | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-69c3-5xxf-58q2 SQL injection in moodle | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-6922-5v25-p8jg Moodle multiple cross-site scripting (XSS) vulnerabilities | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-68x5-4jg5-gjgg Moodle CSRF risk in analytics management of models | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
GHSA-68fm-qg53-rwwj SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int. | 3% Низкий | больше 4 лет назад |
Уязвимостей на страницу