Количество 2 541
Количество 2 541

CVE-2021-36396
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
CVE-2021-36396
In Moodle, insufficient redirect handling made it possible to blindly ...

CVE-2021-36395
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

CVE-2021-36395
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
CVE-2021-36395
In Moodle, the file repository's URL parsing required additional recur ...

CVE-2021-36394
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

CVE-2021-36394
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36394
In Moodle, a remote code execution risk was identified in the Shibbole ...

CVE-2021-36393
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

CVE-2021-36393
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
CVE-2021-36393
In Moodle, an SQL injection risk was identified in the library fetchin ...

CVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

CVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetchin ...

CVE-2021-32478
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

CVE-2021-32478
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
CVE-2021-32478
The redirect URI in the LTI authorization endpoint required extra sani ...

CVE-2021-32477
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.

CVE-2021-32477
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
CVE-2021-32477
The last time a user accessed the mobile app is displayed on their pro ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2021-36396 In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад |
CVE-2021-36396 In Moodle, insufficient redirect handling made it possible to blindly ... | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
![]() | CVE-2021-36395 In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2021-36395 In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад |
CVE-2021-36395 In Moodle, the file repository's URL parsing required additional recur ... | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2021-36394 In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | CVSS3: 9.8 | 19% Средний | больше 2 лет назад |
![]() | CVE-2021-36394 In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | CVSS3: 9.8 | 19% Средний | больше 2 лет назад |
CVE-2021-36394 In Moodle, a remote code execution risk was identified in the Shibbole ... | CVSS3: 9.8 | 19% Средний | больше 2 лет назад | |
![]() | CVE-2021-36393 In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | CVSS3: 9.8 | 25% Средний | больше 2 лет назад |
![]() | CVE-2021-36393 In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | CVSS3: 9.8 | 25% Средний | больше 2 лет назад |
CVE-2021-36393 In Moodle, an SQL injection risk was identified in the library fetchin ... | CVSS3: 9.8 | 25% Средний | больше 2 лет назад | |
![]() | CVE-2021-36392 In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад |
![]() | CVE-2021-36392 In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад |
CVE-2021-36392 In Moodle, an SQL injection risk was identified in the library fetchin ... | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
![]() | CVE-2021-32478 The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected. | CVSS3: 6.1 | 4% Низкий | больше 3 лет назад |
![]() | CVE-2021-32478 The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected. | CVSS3: 6.1 | 4% Низкий | больше 3 лет назад |
CVE-2021-32478 The redirect URI in the LTI authorization endpoint required extra sani ... | CVSS3: 6.1 | 4% Низкий | больше 3 лет назад | |
![]() | CVE-2021-32477 The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2021-32477 The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
CVE-2021-32477 The last time a user accessed the mobile app is displayed on their pro ... | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу