Количество 2 643
Количество 2 643
CVE-2025-62395
A flaw in the cohort search web service allowed users with permissions ...
CVE-2025-62394
Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.
CVE-2025-62394
Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.
CVE-2025-62394
Moodle failed to verify enrolment status correctly when sending quiz n ...
CVE-2025-62393
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
CVE-2025-62393
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
CVE-2025-62393
A flaw was found in the course overview output function where user acc ...
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...
CVE-2025-3647
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
CVE-2025-3647
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
CVE-2025-3647
A flaw was discovered in Moodle. Additional checks were required to en ...
CVE-2025-3645
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.
CVE-2025-3645
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.
CVE-2025-3645
A flaw was found in Moodle. Insufficient capability checks in a messag ...
CVE-2025-3644
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
CVE-2025-3644
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
CVE-2025-3644
A flaw was found in Moodle. Additional checks were required to prevent ...
CVE-2025-3643
A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-62395 A flaw in the cohort search web service allowed users with permissions ... | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-62394 Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-62394 Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-62394 Moodle failed to verify enrolment status correctly when sending quiz n ... | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-62393 A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-62393 A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-62393 A flaw was found in the course overview output function where user acc ... | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 6 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | 6 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ... | CVSS3: 4.2 | 0% Низкий | 6 месяцев назад | |
CVE-2025-3647 A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3647 A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3647 A flaw was discovered in Moodle. Additional checks were required to en ... | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3645 A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3645 A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3645 A flaw was found in Moodle. Insufficient capability checks in a messag ... | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3644 A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3644 A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3644 A flaw was found in Moodle. Additional checks were required to prevent ... | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
CVE-2025-3643 A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу