Количество 2 712
Количество 2 712
GHSA-3rqj-jchw-9cc7
Moodle Authentication Bypass in Question-Bank
GHSA-3r5w-g4xg-c8cv
Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.
GHSA-3r38-g3wv-x66q
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.
GHSA-3qw5-v9cc-v262
Cross site scripting in moodle
GHSA-3qg4-2fcm-c8f9
Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members
GHSA-3mfq-73xr-2v9w
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
GHSA-3m99-h3hp-w9j7
Moodle remote code execution via quiz questions
GHSA-3jh2-34x2-mr98
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
GHSA-3jfw-v39g-268j
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
GHSA-3hmr-948v-5qgq
Moodle Cross-Site Request Forgery (CSRF)
GHSA-3gm8-32vv-q8mp
Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter
GHSA-3fj7-9j8m-7r8g
Moodle Stored HTML in assignment submission comments allowed links to be opened directly
GHSA-3f43-8vw5-xcf9
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.
GHSA-398j-f7m7-795j
PHPMailer vulnerable to email header injection
GHSA-389j-qw4x-m76h
Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.
GHSA-382v-gxj9-ffhc
Moodle uses predictable password-recovery tokens
GHSA-37mm-gc69-pw8r
Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).
GHSA-36cm-vrqh-8p98
Moodle allows attackers to cause a denial of service
GHSA-35wf-3wq2-r3hx
Moodle has Incorrect Default Permissions
GHSA-35pr-gqm6-r366
Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3rqj-jchw-9cc7 Moodle Authentication Bypass in Question-Bank | 1% Низкий | около 4 лет назад | ||
GHSA-3r5w-g4xg-c8cv Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php. | 1% Низкий | около 4 лет назад | ||
GHSA-3r38-g3wv-x66q Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php. | 1% Низкий | около 4 лет назад | ||
GHSA-3qw5-v9cc-v262 Cross site scripting in moodle | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-3qg4-2fcm-c8f9 Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members | 2% Низкий | около 4 лет назад | ||
GHSA-3mfq-73xr-2v9w repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field. | 1% Низкий | около 4 лет назад | ||
GHSA-3m99-h3hp-w9j7 Moodle remote code execution via quiz questions | 2% Низкий | около 4 лет назад | ||
GHSA-3jh2-34x2-mr98 Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-3jfw-v39g-268j Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding. | 1% Низкий | около 4 лет назад | ||
GHSA-3hmr-948v-5qgq Moodle Cross-Site Request Forgery (CSRF) | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-3gm8-32vv-q8mp Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter | 2% Низкий | около 4 лет назад | ||
GHSA-3fj7-9j8m-7r8g Moodle Stored HTML in assignment submission comments allowed links to be opened directly | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-3f43-8vw5-xcf9 Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field. | 1% Низкий | около 4 лет назад | ||
GHSA-398j-f7m7-795j PHPMailer vulnerable to email header injection | 2% Низкий | почти 4 года назад | ||
GHSA-389j-qw4x-m76h Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-382v-gxj9-ffhc Moodle uses predictable password-recovery tokens | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-37mm-gc69-pw8r Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title). | 2% Низкий | около 4 лет назад | ||
GHSA-36cm-vrqh-8p98 Moodle allows attackers to cause a denial of service | 2% Низкий | около 4 лет назад | ||
GHSA-35wf-3wq2-r3hx Moodle has Incorrect Default Permissions | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-35pr-gqm6-r366 Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу