Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

github логотип

GHSA-vj5p-fp42-774p

больше 3 лет назад

Moodle may display roles to users who don't have access to them

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-vg4g-6rhx-p7rr

около 4 лет назад

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vcvh-qrpm-8cw7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

EPSS: Низкий
github логотип

GHSA-v9xq-vh72-chr4

около 4 лет назад

Moodle Unauthenticated users can trigger custom messages to admin via paypal enrol script

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-v6f4-v8h8-3c87

больше 1 года назад

Moodle Remote Code Execution vulnerability

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-v52c-rjhj-v6hm

около 4 лет назад

Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.

EPSS: Низкий
github логотип

GHSA-v3wp-35g3-m9mm

около 4 лет назад

Moodle does not consider the moodle/tag:flag capability

EPSS: Низкий
github логотип

GHSA-v33x-q8gh-4x42

около 4 лет назад

Moodle multiple cross-site request forgery (CSRF) vulnerabilities

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-v2rh-5v88-rgvh

около 4 лет назад

Moodle context freezing

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rvmc-8gmg-ggqr

больше 4 лет назад

Moodle Blind SQL injection possible via MNet authentication

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-rv62-6f56-j83w

около 4 лет назад

Moodle Oauth 2 Insufficiently Protects Against Compromise

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-rmq4-phgg-pxp4

больше 4 лет назад

Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.

EPSS: Низкий
github логотип

GHSA-rmfm-w44g-h6m2

около 4 лет назад

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

EPSS: Низкий
github логотип

GHSA-rmcv-83m2-7x23

около 4 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

EPSS: Низкий
github логотип

GHSA-rjh8-w8jg-xwq5

около 4 лет назад

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rjcm-7v2p-9265

9 месяцев назад

Moodle course access permissions are not properly checked in course_output_fragment_course_overview

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-rj5x-jhhc-5x6h

около 4 лет назад

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.

EPSS: Низкий
github логотип

GHSA-rgmc-f85q-83hm

больше 4 лет назад

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

EPSS: Низкий
github логотип

GHSA-rg56-94j7-hjx9

больше 1 года назад

Moodle has a SQL injection risk in course search module list filter

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-rc65-mhj4-hp4r

9 месяцев назад

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vj5p-fp42-774p

Moodle may display roles to users who don't have access to them

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-vg4g-6rhx-p7rr

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-vcvh-qrpm-8cw7

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

2%
Низкий
около 4 лет назад
github логотип
GHSA-v9xq-vh72-chr4

Moodle Unauthenticated users can trigger custom messages to admin via paypal enrol script

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-v6f4-v8h8-3c87

Moodle Remote Code Execution vulnerability

CVSS3: 8.1
83%
Высокий
больше 1 года назад
github логотип
GHSA-v52c-rjhj-v6hm

Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.

1%
Низкий
около 4 лет назад
github логотип
GHSA-v3wp-35g3-m9mm

Moodle does not consider the moodle/tag:flag capability

2%
Низкий
около 4 лет назад
github логотип
GHSA-v33x-q8gh-4x42

Moodle multiple cross-site request forgery (CSRF) vulnerabilities

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-v2rh-5v88-rgvh

Moodle context freezing

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-rvmc-8gmg-ggqr

Moodle Blind SQL injection possible via MNet authentication

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-rv62-6f56-j83w

Moodle Oauth 2 Insufficiently Protects Against Compromise

CVSS3: 9.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-rmq4-phgg-pxp4

Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-rmfm-w44g-h6m2

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

1%
Низкий
около 4 лет назад
github логотип
GHSA-rmcv-83m2-7x23

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

4%
Низкий
около 4 лет назад
github логотип
GHSA-rjh8-w8jg-xwq5

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-rjcm-7v2p-9265

Moodle course access permissions are not properly checked in course_output_fragment_course_overview

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-rj5x-jhhc-5x6h

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-rgmc-f85q-83hm

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

1%
Низкий
больше 4 лет назад
github логотип
GHSA-rg56-94j7-hjx9

Moodle has a SQL injection risk in course search module list filter

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-rc65-mhj4-hp4r

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

CVSS3: 5.3
0%
Низкий
9 месяцев назад

Уязвимостей на страницу