Exposición de Moodle

LMS
74
score de exposición
10.577
sitios usan
0
en explotación
8
críticos
Análisis Vexday

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 resultados
CVE-2021-20282When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle beEPSS 1.3%CVE-2012-1160Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.phpEPSS 1.2%CVE-2017-7489In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.EPSS 1.2%CVE-2012-1157Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by defaultEPSS 1.2%CVE-2016-8642In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.EPSS 1.2%CVE-2023-28329MEDIUMMoodle: authenticated sql injection via availability checkEPSS 1.2%CVE-2018-1135An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle filEPSS 1.2%CVE-2023-28330MEDIUMMoodle: authenticated arbitrary file read through malformed backup fileEPSS 1.2%CVE-2016-8644In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.EPSS 1.2%CVE-2023-28333CRITICALMoodle: pix helper potential mustache code injection riskEPSS 1.2%CVE-2023-5546MEDIUMMoodle: stored xss in quiz grading report via user id numberEPSS 1.2%CVE-2017-15110In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students cEPSS 1.2%CVE-2023-30944MEDIUMMoodle: minor sql injection risk in external wiki method for listing pagesEPSS 1.1%CVE-2021-32478The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versioEPSS 1.1%CVE-2022-30598A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise haEPSS 1.1%CVE-2019-14881MEDIUMA vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.EPSS 1.1%CVE-2019-14880MEDIUMA vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not EPSS 1.1%CVE-2019-3808MEDIUMA flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage grEPSS 1.1%CVE-2019-14883LOWA vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notificatioEPSS 1.1%CVE-2019-10186MEDIUMA flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading aEPSS 1.1%