Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

ubuntu логотип

CVE-2023-28333

больше 2 лет назад

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-28333

больше 2 лет назад

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-28333

больше 2 лет назад

The Mustache pix helper contained a potential Mustache injection risk ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-28332

больше 2 лет назад

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-28332

больше 2 лет назад

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-28332

больше 2 лет назад

If the algebra filter was enabled but not functional (eg the necessary ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2023-28331

больше 2 лет назад

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-28331

больше 2 лет назад

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-28331

больше 2 лет назад

Content output by the database auto-linking filter required additional ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2023-28330

больше 2 лет назад

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-28330

больше 2 лет назад

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-28330

больше 2 лет назад

Insufficient sanitizing in backup resulted in an arbitrary file read r ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-28329

больше 2 лет назад

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-28329

больше 2 лет назад

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-28329

больше 2 лет назад

Insufficient validation of profile field availability condition result ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2023-23923

больше 2 лет назад

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2023-23923

больше 2 лет назад

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

CVSS3: 8.2
EPSS: Низкий
debian логотип

CVE-2023-23923

больше 2 лет назад

The vulnerability was found Moodle which exists due to insufficient li ...

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2023-23922

больше 2 лет назад

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-23922

больше 2 лет назад

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-28333

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28333

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28333

The Mustache pix helper contained a potential Mustache injection risk ...

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-28332

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28332

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28332

If the algebra filter was enabled but not functional (eg the necessary ...

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-28331

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28331

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28331

Content output by the database auto-linking filter required additional ...

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-28330

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28330

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28330

Insufficient sanitizing in backup resulted in an arbitrary file read r ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-28329

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28329

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28329

Insufficient validation of profile field availability condition result ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-23923

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23923

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23923

The vulnerability was found Moodle which exists due to insufficient li ...

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-23922

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23922

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website. This flaw allows a remote attacker to perform cross-site scripting (XSS) attacks.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу