Количество 2 712
Количество 2 712
GHSA-688p-pgj4-77hh
Moodle allows attackers to obtain sensitive course-structure information
GHSA-683c-cq88-f22q
** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."
GHSA-66xp-28cq-mrf2
Moodle Denial of Service
GHSA-6656-6qwx-4c2m
Moodle XSS In Tag Autocomplete functionality
GHSA-664q-mrxx-2x2v
Moodle does not properly manage privileges for WebDAV repositories
GHSA-659w-gh8v-v435
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
GHSA-62wv-866c-rh86
Moodle does not properly restrict comment capabilities
GHSA-62wh-m4jr-233r
Moodle LTI module reflected XSS risk
GHSA-625r-4rf7-g699
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
GHSA-622h-cjgg-5mx6
Moodle allows attackers to bypass file-management restrictions
GHSA-5xqf-3mwv-q7gm
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.
GHSA-5xp2-rv4h-mm2q
Moodle Open Redirect Vulnerability
GHSA-5x33-h32w-6vr2
Cross site-scripting (XSS) moodle
GHSA-5wjh-v7c8-wrhx
Moodle stored Cross-site Scripting
GHSA-5wg9-5w3f-hxmh
Moodle Users could elevate their role when accessing the LTI tool on a provider site
GHSA-5w4h-xrr5-7273
Moodle Exposure of Sensitive Information to an Unauthorized Actor
GHSA-5rr5-fxhc-jv64
Moodle allows attackers to modify the visibility of a badge
GHSA-5r85-6h7f-rg3r
Moodle's non-searchable tags can still be discovered on the tag search page and in the tags block
GHSA-5p2x-8427-9fgp
Moodle Improper Access Control vulnerability
GHSA-5jph-mvfm-r27p
Moodle cross-site request forgery (CSRF) vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-688p-pgj4-77hh Moodle allows attackers to obtain sensitive course-structure information | 2% Низкий | около 4 лет назад | ||
GHSA-683c-cq88-f22q ** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields." | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-66xp-28cq-mrf2 Moodle Denial of Service | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-6656-6qwx-4c2m Moodle XSS In Tag Autocomplete functionality | 2% Низкий | около 4 лет назад | ||
GHSA-664q-mrxx-2x2v Moodle does not properly manage privileges for WebDAV repositories | 2% Низкий | около 4 лет назад | ||
GHSA-659w-gh8v-v435 lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file. | 1% Низкий | около 4 лет назад | ||
GHSA-62wv-866c-rh86 Moodle does not properly restrict comment capabilities | 2% Низкий | около 4 лет назад | ||
GHSA-62wh-m4jr-233r Moodle LTI module reflected XSS risk | CVSS3: 6.1 | 4% Низкий | около 4 лет назад | |
GHSA-625r-4rf7-g699 In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool. | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-622h-cjgg-5mx6 Moodle allows attackers to bypass file-management restrictions | 2% Низкий | около 4 лет назад | ||
GHSA-5xqf-3mwv-q7gm Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-5xp2-rv4h-mm2q Moodle Open Redirect Vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-5x33-h32w-6vr2 Cross site-scripting (XSS) moodle | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
GHSA-5wjh-v7c8-wrhx Moodle stored Cross-site Scripting | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-5wg9-5w3f-hxmh Moodle Users could elevate their role when accessing the LTI tool on a provider site | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-5w4h-xrr5-7273 Moodle Exposure of Sensitive Information to an Unauthorized Actor | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-5rr5-fxhc-jv64 Moodle allows attackers to modify the visibility of a badge | 2% Низкий | около 4 лет назад | ||
GHSA-5r85-6h7f-rg3r Moodle's non-searchable tags can still be discovered on the tag search page and in the tags block | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-5p2x-8427-9fgp Moodle Improper Access Control vulnerability | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-5jph-mvfm-r27p Moodle cross-site request forgery (CSRF) vulnerability | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу