Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-4fm4-pcw7-99hg

около 4 лет назад

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

EPSS: Низкий
github логотип

GHSA-4c5g-w3gf-rf4f

около 4 лет назад

Moodle allows attackers to obtain username and course information

EPSS: Низкий
github логотип

GHSA-49mv-vfcp-8gg9

около 3 лет назад

Moodle vulnerable to SQL Injection

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-48rq-vj58-2mh6

около 4 лет назад

Moodle creates a MoodleMobile web-service token with an infinite lifetime

EPSS: Низкий
github логотип

GHSA-487g-3m3v-hjhq

больше 2 лет назад

Uncontrolled Resource Consumption in moodle

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-47cw-whh9-j2fq

около 4 лет назад

Moodle allows attacks to obtain sensitive information

EPSS: Низкий
github логотип

GHSA-4794-5xw8-8vrg

около 4 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

EPSS: Низкий
github логотип

GHSA-475h-wv64-r896

около 4 лет назад

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

EPSS: Низкий
github логотип

GHSA-468q-9cmp-76wc

около 4 лет назад

Moodle does not consider the moodle/tag:edit capability before adding a tag

EPSS: Низкий
github логотип

GHSA-45rw-4r25-jvg7

около 4 лет назад

Moodle Logged in users could view all calendar events

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-454r-jccq-96q8

больше 4 лет назад

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-454r-4cjv-vc9h

около 4 лет назад

Moodle allows attackers to obtain manager privileges

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-44xp-wj24-9xxj

около 4 лет назад

Moodle allows attackers to delete files

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4452-2568-9wpm

около 4 лет назад

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-43r4-vm25-qm78

около 4 лет назад

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

EPSS: Низкий
github логотип

GHSA-4265-mh49-263h

почти 4 года назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-422v-w6c5-vq42

9 месяцев назад

Moodle exposed the names of hidden groups to users

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3xh5-5v5v-mfgm

около 4 лет назад

Moodle reflected Cross-site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3w4p-mc7m-x3qf

около 4 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

EPSS: Низкий
github логотип

GHSA-3vcq-64gh-84x2

больше 4 лет назад

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4fm4-pcw7-99hg

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

1%
Низкий
около 4 лет назад
github логотип
GHSA-4c5g-w3gf-rf4f

Moodle allows attackers to obtain username and course information

1%
Низкий
около 4 лет назад
github логотип
GHSA-49mv-vfcp-8gg9

Moodle vulnerable to SQL Injection

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-48rq-vj58-2mh6

Moodle creates a MoodleMobile web-service token with an infinite lifetime

3%
Низкий
около 4 лет назад
github логотип
GHSA-487g-3m3v-hjhq

Uncontrolled Resource Consumption in moodle

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-47cw-whh9-j2fq

Moodle allows attacks to obtain sensitive information

2%
Низкий
около 4 лет назад
github логотип
GHSA-4794-5xw8-8vrg

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

1%
Низкий
около 4 лет назад
github логотип
GHSA-475h-wv64-r896

Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

1%
Низкий
около 4 лет назад
github логотип
GHSA-468q-9cmp-76wc

Moodle does not consider the moodle/tag:edit capability before adding a tag

2%
Низкий
около 4 лет назад
github логотип
GHSA-45rw-4r25-jvg7

Moodle Logged in users could view all calendar events

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-454r-jccq-96q8

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-454r-4cjv-vc9h

Moodle allows attackers to obtain manager privileges

CVSS3: 6.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-44xp-wj24-9xxj

Moodle allows attackers to delete files

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-4452-2568-9wpm

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-43r4-vm25-qm78

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

1%
Низкий
около 4 лет назад
github логотип
GHSA-4265-mh49-263h

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-422v-w6c5-vq42

Moodle exposed the names of hidden groups to users

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3xh5-5v5v-mfgm

Moodle reflected Cross-site Scripting (XSS)

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3w4p-mc7m-x3qf

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

2%
Низкий
около 4 лет назад
github логотип
GHSA-3vcq-64gh-84x2

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу