Количество 2 712
Количество 2 712
GHSA-4wvg-7886-83gv
Moodle cross-site request forgery (CSRF) vulnerability
GHSA-4w8m-96v9-2c86
Moodle CRLF Injection Vulnerability in Calendar Component
GHSA-4w4j-9533-82qg
Moodle Cross-site Scripting (XSS)
GHSA-4w32-c9g7-27qx
Moodle allows reflected XSS via question bank filter
GHSA-4vfx-5fp5-jh6f
Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-4rmj-w58m-fvch
Moodle vulnerable to Server-Side Request Forgery
GHSA-4r9p-m9h5-r8vm
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.
GHSA-4r4x-49qh-hfgv
Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.
GHSA-4r2p-wpv5-683w
Moodle XSS Vulnerability
GHSA-4qxc-qxrp-33cw
Moodle denial-of-service risk in the draft files area
GHSA-4qww-rxq6-x7gf
Moodle broken access control when setting calendar event type
GHSA-4pv6-rw85-g6wg
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.
GHSA-4ppg-2mx6-fqx9
Moodle allows attackers to bypass intended login restrictions
GHSA-4m6v-x9fj-847j
Moodle Cross-site Scripting in the Course summary filter of the Add a new course
GHSA-4jm2-c9jr-6prf
Moodle allows attackers to bypass a messaging-disabled setting
GHSA-4jc7-gpxx-gg52
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
GHSA-4hmr-39vp-xfrr
Moodle has an arbitrary file read risk through pdfTeX
GHSA-4hjf-6pxr-549h
Moodle Cross-site Scripting vulnerability
GHSA-4gq2-x5w4-7hp8
Moodle has insufficient capability checks
GHSA-4g4j-v56v-2w79
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4wvg-7886-83gv Moodle cross-site request forgery (CSRF) vulnerability | 1% Низкий | около 4 лет назад | ||
GHSA-4w8m-96v9-2c86 Moodle CRLF Injection Vulnerability in Calendar Component | 1% Низкий | около 4 лет назад | ||
GHSA-4w4j-9533-82qg Moodle Cross-site Scripting (XSS) | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-4w32-c9g7-27qx Moodle allows reflected XSS via question bank filter | CVSS3: 8.3 | 0% Низкий | больше 1 года назад | |
GHSA-4vfx-5fp5-jh6f Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 2% Низкий | больше 4 лет назад | ||
GHSA-4rmj-w58m-fvch Moodle vulnerable to Server-Side Request Forgery | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-4r9p-m9h5-r8vm Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r4x-49qh-hfgv Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens. | 1% Низкий | около 4 лет назад | ||
GHSA-4r2p-wpv5-683w Moodle XSS Vulnerability | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-4qxc-qxrp-33cw Moodle denial-of-service risk in the draft files area | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4qww-rxq6-x7gf Moodle broken access control when setting calendar event type | CVSS3: 6.2 | 0% Низкий | около 2 лет назад | |
GHSA-4pv6-rw85-g6wg theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response. | 1% Низкий | около 4 лет назад | ||
GHSA-4ppg-2mx6-fqx9 Moodle allows attackers to bypass intended login restrictions | 2% Низкий | около 4 лет назад | ||
GHSA-4m6v-x9fj-847j Moodle Cross-site Scripting in the Course summary filter of the Add a new course | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-4jm2-c9jr-6prf Moodle allows attackers to bypass a messaging-disabled setting | 2% Низкий | около 4 лет назад | ||
GHSA-4jc7-gpxx-gg52 The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation. | 2% Низкий | около 4 лет назад | ||
GHSA-4hmr-39vp-xfrr Moodle has an arbitrary file read risk through pdfTeX | CVSS3: 8.6 | 0% Низкий | больше 1 года назад | |
GHSA-4hjf-6pxr-549h Moodle Cross-site Scripting vulnerability | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-4gq2-x5w4-7hp8 Moodle has insufficient capability checks | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-4g4j-v56v-2w79 A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server. | CVSS3: 7.2 | 2% Низкий | 5 месяцев назад |
Уязвимостей на страницу