Количество 2 712
Количество 2 712
GHSA-358r-g2xw-7c83
Moodle backs up private files
GHSA-356g-7x36-7m34
Moodle CSRF risks due to misuse of confirm_sesskey
GHSA-34g7-pg9j-pxgp
Moodle allows IDOR when accessing the cohorts report
GHSA-345q-9jmq-g9q4
Moodle allows unauthenticated REST API user data exposure
GHSA-332g-xh34-5c96
Moodle Privilege escalation in quiz web services
GHSA-32jc-9p58-p82x
Moodle Improper Access Control vulnerability
GHSA-32hg-73hp-vwc8
Moodle allows attackers to modify "Exclude grade" settings
GHSA-2x36-7xfm-pgm7
Moodle default permissions too permissive
GHSA-2wmj-8mqg-r9q8
Moodle has Incorrect Default Permissions
GHSA-2vhr-4mhq-m35c
Moodle does not properly restrict access
GHSA-2r9m-wg35-rfvc
Moodle vulnerable to cache poisoning via injection into storage
GHSA-2phx-w35g-x9vm
Moodle Weak Password Recovery Mechanism for Forgotten Password
GHSA-2mg9-hv69-897x
Moodle Ability to delete glossary entries that belong to another glossary
GHSA-2mf2-xc34-hpjc
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.
GHSA-2m72-m5cw-3g9h
Missing permission check in Moodle
GHSA-2jxg-mv2m-j4r7
Moodle type juggling vulnerability
GHSA-2jrm-gww7-wch2
Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration
GHSA-2jcw-r79x-4r5v
Moodle does not set the RISK_XSS bit for graders
GHSA-2hw8-qj3h-c7pq
badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.
GHSA-2hw6-6rgf-726v
Moodle XSS Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-358r-g2xw-7c83 Moodle backs up private files | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-356g-7x36-7m34 Moodle CSRF risks due to misuse of confirm_sesskey | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-34g7-pg9j-pxgp Moodle allows IDOR when accessing the cohorts report | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-345q-9jmq-g9q4 Moodle allows unauthenticated REST API user data exposure | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-332g-xh34-5c96 Moodle Privilege escalation in quiz web services | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-32jc-9p58-p82x Moodle Improper Access Control vulnerability | CVSS3: 8.2 | 1% Низкий | больше 3 лет назад | |
GHSA-32hg-73hp-vwc8 Moodle allows attackers to modify "Exclude grade" settings | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-2x36-7xfm-pgm7 Moodle default permissions too permissive | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-2wmj-8mqg-r9q8 Moodle has Incorrect Default Permissions | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-2vhr-4mhq-m35c Moodle does not properly restrict access | 1% Низкий | около 4 лет назад | ||
GHSA-2r9m-wg35-rfvc Moodle vulnerable to cache poisoning via injection into storage | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
GHSA-2phx-w35g-x9vm Moodle Weak Password Recovery Mechanism for Forgotten Password | CVSS3: 7.3 | 1% Низкий | около 4 лет назад | |
GHSA-2mg9-hv69-897x Moodle Ability to delete glossary entries that belong to another glossary | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-2mf2-xc34-hpjc course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation. | 1% Низкий | около 4 лет назад | ||
GHSA-2m72-m5cw-3g9h Missing permission check in Moodle | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-2jxg-mv2m-j4r7 Moodle type juggling vulnerability | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-2jrm-gww7-wch2 Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration | CVSS3: 7.2 | 2% Низкий | около 4 лет назад | |
GHSA-2jcw-r79x-4r5v Moodle does not set the RISK_XSS bit for graders | 1% Низкий | около 4 лет назад | ||
GHSA-2hw8-qj3h-c7pq badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-2hw6-6rgf-726v Moodle XSS Vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу