Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

debian логотип

CVE-2020-25700

больше 4 лет назад

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-25699

больше 4 лет назад

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-25699

больше 4 лет назад

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-25699

больше 4 лет назад

In moodle, insufficient capability checks could lead to users with the ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-25698

больше 4 лет назад

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-25698

больше 4 лет назад

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-25698

больше 4 лет назад

Users' enrollment capabilities were not being sufficiently checked in ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-25631

больше 4 лет назад

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25631

больше 4 лет назад

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25631

больше 4 лет назад

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-25630

больше 4 лет назад

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-25630

больше 4 лет назад

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-25630

больше 4 лет назад

A vulnerability was found in Moodle where the decompressed size of zip ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2020-25629

больше 4 лет назад

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-25629

больше 4 лет назад

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-25629

больше 4 лет назад

A vulnerability was found in Moodle where users with "Log in as" capab ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-25628

больше 4 лет назад

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-25628

больше 4 лет назад

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-25628

больше 4 лет назад

The filter in the tag manager required extra sanitizing to prevent a r ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-25627

больше 4 лет назад

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2020-25700

In moodle, some database module web services allowed students to add e ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ...

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25698

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25698

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25698

Users' enrollment capabilities were not being sufficiently checked in ...

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25631

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25631

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25631

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip ...

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. This is fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capab ...

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25628

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-25628

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-25628

The filter in the tag manager required extra sanitizing to prevent a r ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

CVSS3: 6.1
5%
Низкий
больше 4 лет назад

Уязвимостей на страницу