Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

ubuntu логотип

CVE-2021-20185

больше 4 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-20185

больше 4 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-20185

больше 4 лет назад

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2021-20184

больше 4 лет назад

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-20184

больше 4 лет назад

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-20184

больше 4 лет назад

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a i ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-20183

больше 4 лет назад

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2021-20183

больше 4 лет назад

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2021-20183

больше 4 лет назад

It was found in Moodle before version 3.10.1 that some search inputs w ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2020-25703

больше 4 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25703

больше 4 лет назад

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25703

больше 4 лет назад

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-25702

больше 4 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25702

больше 4 лет назад

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25702

больше 4 лет назад

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-25701

больше 4 лет назад

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-25701

больше 4 лет назад

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-25701

больше 4 лет назад

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-25700

больше 4 лет назад

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-25700

больше 4 лет назад

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-20184

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-20184

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-20184

It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a i ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-20183

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-20183

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-20183

It was found in Moodle before version 3.10.1 that some search inputs w ...

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25703

The participants table download in Moodle always included user emails, ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming conten ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment m ...

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу