Количество 2 470
Количество 2 470
CVE-2022-0984
Users with the capability to configure badge criteria (teachers and ma ...

CVE-2022-0335
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

CVE-2022-0335
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.
CVE-2022-0335
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ...

CVE-2022-0334
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.

CVE-2022-0334
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.
CVE-2022-0334
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ...

CVE-2022-0333
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

CVE-2022-0333
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
CVE-2022-0333
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ...

CVE-2022-0332
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

CVE-2022-0332
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
CVE-2022-0332
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injectio ...

CVE-2021-40695
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.

CVE-2021-40695
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
CVE-2021-40695
It was possible for a student to view their quiz grade before it had b ...

CVE-2021-40694
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

CVE-2021-40694
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
CVE-2021-40694
Insufficient escaping of the LaTeX preamble made it possible for site ...

CVE-2021-40693
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2022-0984 Users with the capability to configure badge criteria (teachers and ma ... | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-0335 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2022-0335 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад |
CVE-2022-0335 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ... | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
![]() | CVE-2022-0334 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2022-0334 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
CVE-2022-0334 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ... | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
![]() | CVE-2022-0333 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events. | CVSS3: 3.8 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2022-0333 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events. | CVSS3: 3.8 | 0% Низкий | больше 3 лет назад |
CVE-2022-0333 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ... | CVSS3: 3.8 | 0% Низкий | больше 3 лет назад | |
![]() | CVE-2022-0332 A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад |
![]() | CVE-2022-0332 A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад |
CVE-2022-0332 A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injectio ... | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад | |
![]() | CVE-2021-40695 It was possible for a student to view their quiz grade before it had been released, using a quiz web service. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2021-40695 It was possible for a student to view their quiz grade before it had been released, using a quiz web service. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад |
CVE-2021-40695 It was possible for a student to view their quiz grade before it had b ... | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2021-40694 Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account. | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2021-40694 Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account. | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад |
CVE-2021-40694 Insufficient escaping of the LaTeX preamble made it possible for site ... | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2021-40693 An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу