Количество 2 712
Количество 2 712
CVE-2025-62393
A flaw was found in the course overview output function where user acc ...
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...
CVE-2025-3647
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
CVE-2025-3647
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
CVE-2025-3647
A flaw was discovered in Moodle. Additional checks were required to en ...
CVE-2025-3645
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.
CVE-2025-3645
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.
CVE-2025-3645
A flaw was found in Moodle. Insufficient capability checks in a messag ...
CVE-2025-3644
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
CVE-2025-3644
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
CVE-2025-3644
A flaw was found in Moodle. Additional checks were required to prevent ...
CVE-2025-3643
A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
CVE-2025-3643
A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
CVE-2025-3643
A flaw was found in Moodle. The return URL in the policy tool required ...
CVE-2025-3642
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.
CVE-2025-3642
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.
CVE-2025-3642
A flaw was found in Moodle. A remote code execution risk was identifie ...
CVE-2025-3641
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-62393 A flaw was found in the course overview output function where user acc ... | CVSS3: 4.3 | 0% Низкий | 9 месяцев назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | около 1 года назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 4.2 | 0% Низкий | около 1 года назад | |
CVE-2025-53021 A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ... | CVSS3: 4.2 | 0% Низкий | около 1 года назад | |
CVE-2025-3647 A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3647 A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3647 A flaw was discovered in Moodle. Additional checks were required to en ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3645 A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3645 A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3645 A flaw was found in Moodle. Insufficient capability checks in a messag ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3644 A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3644 A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3644 A flaw was found in Moodle. Additional checks were required to prevent ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
CVE-2025-3643 A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
CVE-2025-3643 A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
CVE-2025-3643 A flaw was found in Moodle. The return URL in the policy tool required ... | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
CVE-2025-3642 A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-3642 A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-3642 A flaw was found in Moodle. A remote code execution risk was identifie ... | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
CVE-2025-3641 A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу