Количество 2 541
Количество 2 541

CVE-2024-33996
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.

CVE-2024-33996
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
CVE-2024-33996
Incorrect validation of allowed event types in a calendar web service ...

CVE-2024-29374
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVE-2024-29374
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

CVE-2024-29374
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
CVE-2024-29374
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3. ...

CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."

CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."
CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentia ...

CVE-2024-25983
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

CVE-2024-25983
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2024-25983
Insufficient checks in a web service made it possible to add comments ...

CVE-2024-25982
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

CVE-2024-25982
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
CVE-2024-25982
The link to update all installed language packs did not include the ne ...

CVE-2024-25981
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVE-2024-25981
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25981
Separate Groups mode restrictions were not honored when performing a f ...

CVE-2024-25980
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-33996 Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to. | CVSS3: 6.2 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-33996 Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to. | CVSS3: 6.2 | 0% Низкий | больше 1 года назад |
CVE-2024-33996 Incorrect validation of allowed event types in a calendar web service ... | CVSS3: 6.2 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-29374 A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-29374 A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-29374 A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад |
CVE-2024-29374 A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3. ... | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle." | CVSS3: 5.4 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle." | CVSS3: 5.4 | 0% Низкий | больше 1 года назад |
CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentia ... | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-25983 Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). | CVSS3: 3.5 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25983 Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). | CVSS3: 3.5 | 0% Низкий | больше 1 года назад |
CVE-2024-25983 Insufficient checks in a web service made it possible to add comments ... | CVSS3: 3.5 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-25982 The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25982 The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
CVE-2024-25982 The link to update all installed language packs did not include the ne ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-25981 Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
![]() | CVE-2024-25981 Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
CVE-2024-25981 Separate Groups mode restrictions were not honored when performing a f ... | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
![]() | CVE-2024-25980 Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу