Exposure of Moodle

LMS
74
exposure score
10,577
sites use
0
exploited
8
critical
Vexday analysis

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 results
CVE-2017-7489In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.EPSS 1.5%CVE-2021-36396HIGHIn Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a bEPSS 1.4%CVE-2022-30599A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.EPSS 1.4%CVE-2012-1159Moodle before 2.2.2: Overview report allows users to see hidden coursesEPSS 1.4%CVE-2018-1081A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users cEPSS 1.4%CVE-2018-1137An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by usEPSS 1.4%CVE-2022-45152CRITICALA blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-suppliEPSS 1.4%CVE-2012-1161Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search resultsEPSS 1.4%CVE-2012-1158Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in exportEPSS 1.4%CVE-2020-25701If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would eEPSS 1.4%CVE-2021-20185It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages,EPSS 1.4%CVE-2023-5550MEDIUMMoodle: rce due to lfi risk in some misconfigured shared hosting environmentsEPSS 1.4%CVE-2020-25630A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping tEPSS 1.4%CVE-2020-25700In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 toEPSS 1.3%CVE-2022-30597A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.EPSS 1.3%CVE-2020-25629A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain accessEPSS 1.3%CVE-2019-10154MEDIUMA flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversationEPSS 1.3%CVE-2021-20281It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.EPSS 1.3%CVE-2020-25702In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodleEPSS 1.3%CVE-2016-7038In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.EPSS 1.3%