Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

github логотип

GHSA-44xp-wj24-9xxj

около 3 лет назад

Moodle allows attackers to delete files

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4452-2568-9wpm

около 3 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-43r4-vm25-qm78

около 3 лет назад

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

EPSS: Низкий
github логотип

GHSA-4265-mh49-263h

почти 3 года назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3xh5-5v5v-mfgm

около 3 лет назад

Moodle reflected Cross-site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3w4p-mc7m-x3qf

около 3 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

EPSS: Низкий
github логотип

GHSA-3vcq-64gh-84x2

около 3 лет назад

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

EPSS: Низкий
github логотип

GHSA-3rqj-jchw-9cc7

около 3 лет назад

Moodle Authentication Bypass in Question-Bank

EPSS: Низкий
github логотип

GHSA-3r5w-g4xg-c8cv

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.

EPSS: Низкий
github логотип

GHSA-3r38-g3wv-x66q

около 3 лет назад

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

EPSS: Низкий
github логотип

GHSA-3qw5-v9cc-v262

больше 1 года назад

Cross site scripting in moodle

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qg4-2fcm-c8f9

около 3 лет назад

Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members

EPSS: Низкий
github логотип

GHSA-3mfq-73xr-2v9w

около 3 лет назад

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

EPSS: Низкий
github логотип

GHSA-3m99-h3hp-w9j7

около 3 лет назад

Moodle remote code execution via quiz questions

EPSS: Низкий
github логотип

GHSA-3jh2-34x2-mr98

около 3 лет назад

Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-3jfw-v39g-268j

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

EPSS: Низкий
github логотип

GHSA-3hmr-948v-5qgq

около 3 лет назад

Moodle Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gm8-32vv-q8mp

около 3 лет назад

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

EPSS: Низкий
github логотип

GHSA-3fj7-9j8m-7r8g

около 3 лет назад

Moodle Stored HTML in assignment submission comments allowed links to be opened directly

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3f43-8vw5-xcf9

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-44xp-wj24-9xxj

Moodle allows attackers to delete files

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-4452-2568-9wpm

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

1%
Низкий
около 3 лет назад
github логотип
GHSA-43r4-vm25-qm78

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

0%
Низкий
около 3 лет назад
github логотип
GHSA-4265-mh49-263h

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3xh5-5v5v-mfgm

Moodle reflected Cross-site Scripting (XSS)

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3w4p-mc7m-x3qf

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3vcq-64gh-84x2

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

1%
Низкий
около 3 лет назад
github логотип
GHSA-3rqj-jchw-9cc7

Moodle Authentication Bypass in Question-Bank

0%
Низкий
около 3 лет назад
github логотип
GHSA-3r5w-g4xg-c8cv

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3r38-g3wv-x66q

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3qw5-v9cc-v262

Cross site scripting in moodle

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qg4-2fcm-c8f9

Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members

0%
Низкий
около 3 лет назад
github логотип
GHSA-3mfq-73xr-2v9w

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3m99-h3hp-w9j7

Moodle remote code execution via quiz questions

1%
Низкий
около 3 лет назад
github логотип
GHSA-3jh2-34x2-mr98

Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3jfw-v39g-268j

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3hmr-948v-5qgq

Moodle Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-3gm8-32vv-q8mp

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

0%
Низкий
около 3 лет назад
github логотип
GHSA-3fj7-9j8m-7r8g

Moodle Stored HTML in assignment submission comments allowed links to be opened directly

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3f43-8vw5-xcf9

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу