Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-4wvg-7886-83gv

около 4 лет назад

Moodle cross-site request forgery (CSRF) vulnerability

EPSS: Низкий
github логотип

GHSA-4w8m-96v9-2c86

около 4 лет назад

Moodle CRLF Injection Vulnerability in Calendar Component

EPSS: Низкий
github логотип

GHSA-4w4j-9533-82qg

около 4 лет назад

Moodle Cross-site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4w32-c9g7-27qx

больше 1 года назад

Moodle allows reflected XSS via question bank filter

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-4vfx-5fp5-jh6f

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-4rmj-w58m-fvch

больше 3 лет назад

Moodle vulnerable to Server-Side Request Forgery

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r9p-m9h5-r8vm

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.

EPSS: Низкий
github логотип

GHSA-4r4x-49qh-hfgv

около 4 лет назад

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

EPSS: Низкий
github логотип

GHSA-4r2p-wpv5-683w

около 4 лет назад

Moodle XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4qxc-qxrp-33cw

больше 4 лет назад

Moodle denial-of-service risk in the draft files area

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qww-rxq6-x7gf

около 2 лет назад

Moodle broken access control when setting calendar event type

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4pv6-rw85-g6wg

около 4 лет назад

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

EPSS: Низкий
github логотип

GHSA-4ppg-2mx6-fqx9

около 4 лет назад

Moodle allows attackers to bypass intended login restrictions

EPSS: Низкий
github логотип

GHSA-4m6v-x9fj-847j

около 4 лет назад

Moodle Cross-site Scripting in the Course summary filter of the Add a new course

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4jm2-c9jr-6prf

около 4 лет назад

Moodle allows attackers to bypass a messaging-disabled setting

EPSS: Низкий
github логотип

GHSA-4jc7-gpxx-gg52

около 4 лет назад

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

EPSS: Низкий
github логотип

GHSA-4hmr-39vp-xfrr

больше 1 года назад

Moodle has an arbitrary file read risk through pdfTeX

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-4hjf-6pxr-549h

больше 1 года назад

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4gq2-x5w4-7hp8

больше 1 года назад

Moodle has insufficient capability checks

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4g4j-v56v-2w79

5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4wvg-7886-83gv

Moodle cross-site request forgery (CSRF) vulnerability

1%
Низкий
около 4 лет назад
github логотип
GHSA-4w8m-96v9-2c86

Moodle CRLF Injection Vulnerability in Calendar Component

1%
Низкий
около 4 лет назад
github логотип
GHSA-4w4j-9533-82qg

Moodle Cross-site Scripting (XSS)

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-4w32-c9g7-27qx

Moodle allows reflected XSS via question bank filter

CVSS3: 8.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4vfx-5fp5-jh6f

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rmj-w58m-fvch

Moodle vulnerable to Server-Side Request Forgery

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4r9p-m9h5-r8vm

Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4x-49qh-hfgv

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4r2p-wpv5-683w

Moodle XSS Vulnerability

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-4qxc-qxrp-33cw

Moodle denial-of-service risk in the draft files area

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qww-rxq6-x7gf

Moodle broken access control when setting calendar event type

CVSS3: 6.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-4pv6-rw85-g6wg

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4ppg-2mx6-fqx9

Moodle allows attackers to bypass intended login restrictions

2%
Низкий
около 4 лет назад
github логотип
GHSA-4m6v-x9fj-847j

Moodle Cross-site Scripting in the Course summary filter of the Add a new course

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-4jm2-c9jr-6prf

Moodle allows attackers to bypass a messaging-disabled setting

2%
Низкий
около 4 лет назад
github логотип
GHSA-4jc7-gpxx-gg52

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

2%
Низкий
около 4 лет назад
github логотип
GHSA-4hmr-39vp-xfrr

Moodle has an arbitrary file read risk through pdfTeX

CVSS3: 8.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-4hjf-6pxr-549h

Moodle Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4gq2-x5w4-7hp8

Moodle has insufficient capability checks

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4g4j-v56v-2w79

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
2%
Низкий
5 месяцев назад

Уязвимостей на страницу