Количество 2 470
Количество 2 470
GHSA-44xp-wj24-9xxj
Moodle allows attackers to delete files
GHSA-4452-2568-9wpm
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.
GHSA-43r4-vm25-qm78
Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module
GHSA-4265-mh49-263h
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
GHSA-3xh5-5v5v-mfgm
Moodle reflected Cross-site Scripting (XSS)
GHSA-3w4p-mc7m-x3qf
Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.
GHSA-3vcq-64gh-84x2
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
GHSA-3rqj-jchw-9cc7
Moodle Authentication Bypass in Question-Bank
GHSA-3r5w-g4xg-c8cv
Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.
GHSA-3r38-g3wv-x66q
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.
GHSA-3qw5-v9cc-v262
Cross site scripting in moodle
GHSA-3qg4-2fcm-c8f9
Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members
GHSA-3mfq-73xr-2v9w
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
GHSA-3m99-h3hp-w9j7
Moodle remote code execution via quiz questions
GHSA-3jh2-34x2-mr98
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
GHSA-3jfw-v39g-268j
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
GHSA-3hmr-948v-5qgq
Moodle Cross-Site Request Forgery (CSRF)
GHSA-3gm8-32vv-q8mp
Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter
GHSA-3fj7-9j8m-7r8g
Moodle Stored HTML in assignment submission comments allowed links to be opened directly
GHSA-3f43-8vw5-xcf9
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-44xp-wj24-9xxj Moodle allows attackers to delete files | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-4452-2568-9wpm Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information. | 1% Низкий | около 3 лет назад | ||
GHSA-43r4-vm25-qm78 Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module | 0% Низкий | около 3 лет назад | ||
GHSA-4265-mh49-263h In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks. | CVSS3: 5.3 | 0% Низкий | почти 3 года назад | |
GHSA-3xh5-5v5v-mfgm Moodle reflected Cross-site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-3w4p-mc7m-x3qf Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path. | 0% Низкий | около 3 лет назад | ||
GHSA-3vcq-64gh-84x2 Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. | 1% Низкий | около 3 лет назад | ||
GHSA-3rqj-jchw-9cc7 Moodle Authentication Bypass in Question-Bank | 0% Низкий | около 3 лет назад | ||
GHSA-3r5w-g4xg-c8cv Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php. | 0% Низкий | около 3 лет назад | ||
GHSA-3r38-g3wv-x66q Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php. | 0% Низкий | около 3 лет назад | ||
GHSA-3qw5-v9cc-v262 Cross site scripting in moodle | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-3qg4-2fcm-c8f9 Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members | 0% Низкий | около 3 лет назад | ||
GHSA-3mfq-73xr-2v9w repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field. | 0% Низкий | около 3 лет назад | ||
GHSA-3m99-h3hp-w9j7 Moodle remote code execution via quiz questions | 1% Низкий | около 3 лет назад | ||
GHSA-3jh2-34x2-mr98 Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors. | 0% Низкий | около 3 лет назад | ||
GHSA-3jfw-v39g-268j Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding. | 0% Низкий | около 3 лет назад | ||
GHSA-3hmr-948v-5qgq Moodle Cross-Site Request Forgery (CSRF) | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-3gm8-32vv-q8mp Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter | 0% Низкий | около 3 лет назад | ||
GHSA-3fj7-9j8m-7r8g Moodle Stored HTML in assignment submission comments allowed links to be opened directly | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-3f43-8vw5-xcf9 Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу