Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

redhat логотип

CVE-2024-29374

больше 1 года назад

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-29374

больше 1 года назад

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-29374

больше 1 года назад

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3. ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2024-28593

больше 1 года назад

** DISPUTED ** The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-28593

больше 1 года назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-28593

больше 1 года назад

The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-25983

больше 1 года назад

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2024-25983

больше 1 года назад

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2024-25983

больше 1 года назад

Insufficient checks in a web service made it possible to add comments ...

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2024-25982

больше 1 года назад

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-25982

больше 1 года назад

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-25982

больше 1 года назад

The link to update all installed language packs did not include the ne ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-25981

больше 1 года назад

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-25981

больше 1 года назад

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-25981

больше 1 года назад

Separate Groups mode restrictions were not honored when performing a f ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-25980

больше 1 года назад

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-25980

больше 1 года назад

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-25980

больше 1 года назад

Separate Groups mode restrictions were not honored in the H5P attempts ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-25979

больше 1 года назад

The URL parameters accepted by forum search were not limited to the allowed parameters.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-25979

больше 1 года назад

The URL parameters accepted by forum search were not limited to the allowed parameters.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3. ...

CVSS3: 6.1
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-28593

** DISPUTED ** The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVSS3: 5.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25983

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVSS3: 3.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-25983

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVSS3: 3.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-25983

Insufficient checks in a web service made it possible to add comments ...

CVSS3: 3.5
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25982

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-25982

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-25982

The link to update all installed language packs did not include the ne ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25981

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-25981

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-25981

Separate Groups mode restrictions were not honored when performing a f ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25980

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-25980

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-25980

Separate Groups mode restrictions were not honored in the H5P attempts ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-25979

The URL parameters accepted by forum search were not limited to the allowed parameters.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-25979

The URL parameters accepted by forum search were not limited to the allowed parameters.

CVSS3: 5.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу