Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2022-40208

больше 2 лет назад

In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-40208

больше 2 лет назад

In Moodle, insufficient limitations in some quiz web services made it ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2022-35653

почти 3 года назад

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

CVSS3: 6.1
EPSS: Высокий
nvd логотип

CVE-2022-35653

почти 3 года назад

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

CVSS3: 6.1
EPSS: Высокий
debian логотип

CVE-2022-35653

почти 3 года назад

A reflected XSS issue was identified in the LTI module of Moodle. The ...

CVSS3: 6.1
EPSS: Высокий
ubuntu логотип

CVE-2022-35652

почти 3 года назад

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-35652

почти 3 года назад

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-35652

почти 3 года назад

An open redirect issue was found in Moodle due to improper sanitizatio ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-35651

почти 3 года назад

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-35651

почти 3 года назад

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-35651

почти 3 года назад

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-35650

почти 3 года назад

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-35650

почти 3 года назад

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-35650

почти 3 года назад

The vulnerability was found in Moodle, occurs due to input validation ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-35649

почти 3 года назад

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-35649

почти 3 года назад

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-35649

почти 3 года назад

The vulnerability was found in Moodle, occurs due to improper input va ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-30600

около 3 лет назад

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-30600

около 3 лет назад

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-30600

около 3 лет назад

A flaw was found in moodle where logic used to count failed login atte ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-40208

In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-40208

In Moodle, insufficient limitations in some quiz web services made it ...

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-35653

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

CVSS3: 6.1
73%
Высокий
почти 3 года назад
nvd логотип
CVE-2022-35653

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks. This vulnerability does not impact authenticated users.

CVSS3: 6.1
73%
Высокий
почти 3 года назад
debian логотип
CVE-2022-35653

A reflected XSS issue was identified in the LTI module of Moodle. The ...

CVSS3: 6.1
73%
Высокий
почти 3 года назад
ubuntu логотип
CVE-2022-35652

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-35652

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-35652

An open redirect issue was found in Moodle due to improper sanitizatio ...

CVSS3: 6.1
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-35651

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-35651

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive information, change appearance of the web page, can perform phishing and drive-by-download attacks.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-35651

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs ...

CVSS3: 6.1
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-35650

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 7.5
9%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-35650

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 7.5
9%
Низкий
почти 3 года назад
debian логотип
CVE-2022-35650

The vulnerability was found in Moodle, occurs due to input validation ...

CVSS3: 7.5
9%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-35649

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

CVSS3: 9.8
4%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-35649

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

CVSS3: 9.8
4%
Низкий
почти 3 года назад
debian логотип
CVE-2022-35649

The vulnerability was found in Moodle, occurs due to improper input va ...

CVSS3: 9.8
4%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-30600

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-30600

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

CVSS3: 9.8
2%
Низкий
около 3 лет назад
debian логотип
CVE-2022-30600

A flaw was found in moodle where logic used to count failed login atte ...

CVSS3: 9.8
2%
Низкий
около 3 лет назад

Уязвимостей на страницу