Количество 2 643
Количество 2 643
GHSA-4265-mh49-263h
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
GHSA-422v-w6c5-vq42
Moodle exposed the names of hidden groups to users
GHSA-3xh5-5v5v-mfgm
Moodle reflected Cross-site Scripting (XSS)
GHSA-3w4p-mc7m-x3qf
Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.
GHSA-3vcq-64gh-84x2
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
GHSA-3rqj-jchw-9cc7
Moodle Authentication Bypass in Question-Bank
GHSA-3r5w-g4xg-c8cv
Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.
GHSA-3r38-g3wv-x66q
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.
GHSA-3qw5-v9cc-v262
Cross site scripting in moodle
GHSA-3qg4-2fcm-c8f9
Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members
GHSA-3mfq-73xr-2v9w
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
GHSA-3m99-h3hp-w9j7
Moodle remote code execution via quiz questions
GHSA-3jh2-34x2-mr98
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
GHSA-3jfw-v39g-268j
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
GHSA-3hmr-948v-5qgq
Moodle Cross-Site Request Forgery (CSRF)
GHSA-3gm8-32vv-q8mp
Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter
GHSA-3fj7-9j8m-7r8g
Moodle Stored HTML in assignment submission comments allowed links to be opened directly
GHSA-3f43-8vw5-xcf9
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.
GHSA-398j-f7m7-795j
PHPMailer vulnerable to email header injection
GHSA-389j-qw4x-m76h
Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4265-mh49-263h In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-422v-w6c5-vq42 Moodle exposed the names of hidden groups to users | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-3xh5-5v5v-mfgm Moodle reflected Cross-site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3w4p-mc7m-x3qf Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path. | 0% Низкий | больше 3 лет назад | ||
GHSA-3vcq-64gh-84x2 Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-3rqj-jchw-9cc7 Moodle Authentication Bypass in Question-Bank | 0% Низкий | больше 3 лет назад | ||
GHSA-3r5w-g4xg-c8cv Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php. | 0% Низкий | больше 3 лет назад | ||
GHSA-3r38-g3wv-x66q Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php. | 0% Низкий | больше 3 лет назад | ||
GHSA-3qw5-v9cc-v262 Cross site scripting in moodle | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-3qg4-2fcm-c8f9 Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members | 0% Низкий | больше 3 лет назад | ||
GHSA-3mfq-73xr-2v9w repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field. | 0% Низкий | больше 3 лет назад | ||
GHSA-3m99-h3hp-w9j7 Moodle remote code execution via quiz questions | 1% Низкий | больше 3 лет назад | ||
GHSA-3jh2-34x2-mr98 Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors. | 1% Низкий | больше 3 лет назад | ||
GHSA-3jfw-v39g-268j Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding. | 0% Низкий | больше 3 лет назад | ||
GHSA-3hmr-948v-5qgq Moodle Cross-Site Request Forgery (CSRF) | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3gm8-32vv-q8mp Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter | 0% Низкий | больше 3 лет назад | ||
GHSA-3fj7-9j8m-7r8g Moodle Stored HTML in assignment submission comments allowed links to be opened directly | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3f43-8vw5-xcf9 Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field. | 0% Низкий | больше 3 лет назад | ||
GHSA-398j-f7m7-795j PHPMailer vulnerable to email header injection | 0% Низкий | около 3 лет назад | ||
GHSA-389j-qw4x-m76h Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php. | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу