Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

github логотип

GHSA-4265-mh49-263h

больше 3 лет назад

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-422v-w6c5-vq42

около 2 месяцев назад

Moodle exposed the names of hidden groups to users

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3xh5-5v5v-mfgm

больше 3 лет назад

Moodle reflected Cross-site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3w4p-mc7m-x3qf

больше 3 лет назад

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

EPSS: Низкий
github логотип

GHSA-3vcq-64gh-84x2

больше 3 лет назад

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

EPSS: Низкий
github логотип

GHSA-3rqj-jchw-9cc7

больше 3 лет назад

Moodle Authentication Bypass in Question-Bank

EPSS: Низкий
github логотип

GHSA-3r5w-g4xg-c8cv

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.

EPSS: Низкий
github логотип

GHSA-3r38-g3wv-x66q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

EPSS: Низкий
github логотип

GHSA-3qw5-v9cc-v262

больше 1 года назад

Cross site scripting in moodle

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qg4-2fcm-c8f9

больше 3 лет назад

Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members

EPSS: Низкий
github логотип

GHSA-3mfq-73xr-2v9w

больше 3 лет назад

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

EPSS: Низкий
github логотип

GHSA-3m99-h3hp-w9j7

больше 3 лет назад

Moodle remote code execution via quiz questions

EPSS: Низкий
github логотип

GHSA-3jh2-34x2-mr98

больше 3 лет назад

Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-3jfw-v39g-268j

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

EPSS: Низкий
github логотип

GHSA-3hmr-948v-5qgq

больше 3 лет назад

Moodle Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gm8-32vv-q8mp

больше 3 лет назад

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

EPSS: Низкий
github логотип

GHSA-3fj7-9j8m-7r8g

больше 3 лет назад

Moodle Stored HTML in assignment submission comments allowed links to be opened directly

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3f43-8vw5-xcf9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

EPSS: Низкий
github логотип

GHSA-398j-f7m7-795j

около 3 лет назад

PHPMailer vulnerable to email header injection

EPSS: Низкий
github логотип

GHSA-389j-qw4x-m76h

больше 3 лет назад

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4265-mh49-263h

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-422v-w6c5-vq42

Moodle exposed the names of hidden groups to users

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3xh5-5v5v-mfgm

Moodle reflected Cross-site Scripting (XSS)

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w4p-mc7m-x3qf

Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vcq-64gh-84x2

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rqj-jchw-9cc7

Moodle Authentication Bypass in Question-Bank

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r5w-g4xg-c8cv

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r38-g3wv-x66q

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qw5-v9cc-v262

Cross site scripting in moodle

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qg4-2fcm-c8f9

Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mfq-73xr-2v9w

repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m99-h3hp-w9j7

Moodle remote code execution via quiz questions

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jh2-34x2-mr98

Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jfw-v39g-268j

Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hmr-948v-5qgq

Moodle Cross-Site Request Forgery (CSRF)

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gm8-32vv-q8mp

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fj7-9j8m-7r8g

Moodle Stored HTML in assignment submission comments allowed links to be opened directly

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f43-8vw5-xcf9

Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-398j-f7m7-795j

PHPMailer vulnerable to email header injection

0%
Низкий
около 3 лет назад
github логотип
GHSA-389j-qw4x-m76h

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу