Количество 2 712
Количество 2 712
GHSA-5hc2-8542-698w
CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
GHSA-5h49-4p8x-9pc2
Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitrary web script or HTML via (1) the choose parameter in files/index.php and (2) the sub parameter in doc/index.php.
GHSA-5fgv-cvr8-xg48
Moodle vulnerable to Cross-site Scripting
GHSA-5cx4-w4fh-fr57
Moodle Affected by Improper Restriction of Excessive Authentication Attempts
GHSA-59w4-qq7r-6mf4
The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.
GHSA-59j6-8g7w-prf7
Moodle exposes hidden grades to students
GHSA-595j-wpfg-23w4
Moodle XSS Vulnerability
GHSA-594q-rvf2-x42j
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.
GHSA-58r8-934v-x9pp
Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators.
GHSA-58fm-v4pr-jh8p
Moodle Unrestricted file upload vulnerability
GHSA-57p3-67r2-vwm7
A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
GHSA-5729-822w-j342
Moodle cross-site scripting (XSS) vulnerability
GHSA-56r9-72vx-q989
Moodle arbitrary file read vulnerability
GHSA-565r-cwvm-gv9r
mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.
GHSA-5659-g9p4-354f
Moodle allows attackers to bypass a forced-password-change requirement
GHSA-557f-2hv4-7jjm
Moodle does not verify group permissions
GHSA-54r2-r67g-fr9m
Moodle User fullname disclosure on user preferences page
GHSA-5488-2xmq-hwfh
Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files.
GHSA-5282-96ff-xx3h
Moodle sensitive information disclosure
GHSA-4xjc-8h53-m2ww
calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-5hc2-8542-698w CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-5h49-4p8x-9pc2 Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitrary web script or HTML via (1) the choose parameter in files/index.php and (2) the sub parameter in doc/index.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-5fgv-cvr8-xg48 Moodle vulnerable to Cross-site Scripting | 2% Низкий | около 4 лет назад | ||
GHSA-5cx4-w4fh-fr57 Moodle Affected by Improper Restriction of Excessive Authentication Attempts | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
GHSA-59w4-qq7r-6mf4 The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction. | 1% Низкий | около 4 лет назад | ||
GHSA-59j6-8g7w-prf7 Moodle exposes hidden grades to students | 2% Низкий | около 4 лет назад | ||
GHSA-595j-wpfg-23w4 Moodle XSS Vulnerability | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-594q-rvf2-x42j Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL. | 1% Низкий | около 4 лет назад | ||
GHSA-58r8-934v-x9pp Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators. | 1% Низкий | больше 4 лет назад | ||
GHSA-58fm-v4pr-jh8p Moodle Unrestricted file upload vulnerability | CVSS3: 8.8 | 4% Низкий | около 4 лет назад | |
GHSA-57p3-67r2-vwm7 A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA). | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-5729-822w-j342 Moodle cross-site scripting (XSS) vulnerability | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-56r9-72vx-q989 Moodle arbitrary file read vulnerability | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-565r-cwvm-gv9r mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-5659-g9p4-354f Moodle allows attackers to bypass a forced-password-change requirement | 2% Низкий | около 4 лет назад | ||
GHSA-557f-2hv4-7jjm Moodle does not verify group permissions | 2% Низкий | около 4 лет назад | ||
GHSA-54r2-r67g-fr9m Moodle User fullname disclosure on user preferences page | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-5488-2xmq-hwfh Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc/locallib.php and certain other files. | 1% Низкий | около 4 лет назад | ||
GHSA-5282-96ff-xx3h Moodle sensitive information disclosure | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-4xjc-8h53-m2ww calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу