Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-6rm3-82c3-gjr8

около 4 лет назад

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

EPSS: Низкий
github логотип

GHSA-6rgj-rxh3-3g5j

больше 4 лет назад

login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action.

EPSS: Низкий
github логотип

GHSA-6r7x-6q98-qcqp

около 4 лет назад

Moodle does not set the RISK_XSS bit for graders

EPSS: Низкий
github логотип

GHSA-6r76-f8c8-fh7p

около 4 лет назад

Moodle Cross-site Scripting in assignment submission page

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6q9g-3vfq-q2qj

больше 4 лет назад

Improper Authentication in moodle

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6q96-wmxp-mc79

около 4 лет назад

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

EPSS: Низкий
github логотип

GHSA-6p3g-hw27-qh44

около 4 лет назад

Moodle's time-validation implementation allows bypassing intended restrictions

EPSS: Низкий
github логотип

GHSA-6mxm-wpqv-675h

около 4 лет назад

Moodle XSS from profile fields from external db

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6mmv-f6c6-v6q8

6 месяцев назад

Moodle vulnerable to Cross-site Scripting

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-6jjc-cvfw-6mr6

больше 4 лет назад

help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

EPSS: Низкий
github логотип

GHSA-6jhm-4vmx-mr76

больше 4 лет назад

SQL injection in Moodle

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-6gx2-g773-hv9h

больше 3 лет назад

Moodle reflected cross-site scripting vulnerability in policy tool

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-6ggr-h9vf-pg47

около 4 лет назад

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

EPSS: Низкий
github логотип

GHSA-6g5x-h5x7-q4mq

больше 1 года назад

Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-69xm-pcg8-8qxm

около 4 лет назад

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-69m9-rprc-2x7g

больше 1 года назад

Moodle reveals student identities through assignment submissions search on anonymous submissions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-69c3-5xxf-58q2

около 4 лет назад

SQL injection in moodle

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-6922-5v25-p8jg

около 4 лет назад

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-68x5-4jg5-gjgg

около 2 лет назад

Moodle CSRF risk in analytics management of models

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-68fm-qg53-rwwj

больше 4 лет назад

SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6rm3-82c3-gjr8

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6rgj-rxh3-3g5j

login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-6r7x-6q98-qcqp

Moodle does not set the RISK_XSS bit for graders

1%
Низкий
около 4 лет назад
github логотип
GHSA-6r76-f8c8-fh7p

Moodle Cross-site Scripting in assignment submission page

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-6q9g-3vfq-q2qj

Improper Authentication in moodle

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-6q96-wmxp-mc79

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6p3g-hw27-qh44

Moodle's time-validation implementation allows bypassing intended restrictions

2%
Низкий
около 4 лет назад
github логотип
GHSA-6mxm-wpqv-675h

Moodle XSS from profile fields from external db

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-6mmv-f6c6-v6q8

Moodle vulnerable to Cross-site Scripting

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-6jjc-cvfw-6mr6

help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-6jhm-4vmx-mr76

SQL injection in Moodle

CVSS3: 9.8
45%
Средний
больше 4 лет назад
github логотип
GHSA-6gx2-g773-hv9h

Moodle reflected cross-site scripting vulnerability in policy tool

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-6ggr-h9vf-pg47

mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying recent feedback, which allows remote authenticated users to obtain sensitive information via a request for all course feedback that has occurred since a specified time.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6g5x-h5x7-q4mq

Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-69xm-pcg8-8qxm

In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-69m9-rprc-2x7g

Moodle reveals student identities through assignment submissions search on anonymous submissions

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-69c3-5xxf-58q2

SQL injection in moodle

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-6922-5v25-p8jg

Moodle multiple cross-site scripting (XSS) vulnerabilities

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-68x5-4jg5-gjgg

Moodle CSRF risk in analytics management of models

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-68fm-qg53-rwwj

SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу