Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 541

Количество 2 541

ubuntu логотип

CVE-2023-5541

почти 2 года назад

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2023-5541

почти 2 года назад

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2023-5541

почти 2 года назад

The CSV grade import method contained an XSS risk for users importing ...

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2023-46858

почти 2 года назад

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-46858

почти 2 года назад

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-46858

почти 2 года назад

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflecte ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2023-35133

около 2 лет назад

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-35133

около 2 лет назад

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-35133

около 2 лет назад

An issue in the logic used to check 0.0.0.0 against the cURL blocked h ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-35132

около 2 лет назад

A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2023-35132

около 2 лет назад

A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2023-35132

около 2 лет назад

A limited SQL injection risk was identified on the Mnet SSO access con ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2023-35131

около 2 лет назад

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-35131

около 2 лет назад

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-35131

около 2 лет назад

Content on the groups page required additional sanitizing to prevent a ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2023-28336

больше 2 лет назад

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-28336

больше 2 лет назад

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-28336

больше 2 лет назад

Insufficient filtering of grade report history made it possible for te ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-28335

больше 2 лет назад

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-28335

больше 2 лет назад

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-5541

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

CVSS3: 3.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-5541

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

CVSS3: 3.3
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-5541

The CSV grade import method contained an XSS risk for users importing ...

CVSS3: 3.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-46858

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-46858

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVSS3: 5.4
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-46858

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflecte ...

CVSS3: 5.4
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-35133

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-35133

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-35133

An issue in the logic used to check 0.0.0.0 against the cURL blocked h ...

CVSS3: 7.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-35132

A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-35132

A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-35132

A limited SQL injection risk was identified on the Mnet SSO access con ...

CVSS3: 6.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-35131

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-35131

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
debian логотип
CVE-2023-35131

Content on the groups page required additional sanitizing to prevent a ...

CVSS3: 6.1
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-28336

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28336

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28336

Insufficient filtering of grade report history made it possible for te ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-28335

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28335

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу