Exposición de Moodle

LMS
74
score de exposición
10.577
sitios usan
0
en explotación
8
críticos
Análisis Vexday

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 resultados
CVE-2019-10188MEDIUMA flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in thEPSS 0.9%CVE-2019-10187MEDIUMA flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete EPSS 0.9%CVE-2019-3851MEDIUMA vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layouEPSS 0.9%CVE-2026-54733CRITICALmoodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpointEPSS 0.9%CVE-2021-43558A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in thEPSS 0.9%CVE-2017-2578In Moodle 3.x, there is XSS in the assignment submission page.EPSS 0.9%CVE-2019-3809MEDIUMA flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of EPSS 0.9%CVE-2023-23922Moodle: reflected xss risk in blog searchEPSS 0.9%CVE-2021-40695It was possible for a student to view their quiz grade before it had been released, using a quiz web service.EPSS 0.9%CVE-2021-36392In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.EPSS 0.8%CVE-2023-35133HIGHMoodle: ssrf risk due to insufficient check on the curl blocked hostsEPSS 0.8%CVE-2021-40693An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.EPSS 0.8%CVE-2019-3850MEDIUMA vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open dEPSS 0.8%CVE-2021-20183It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of searchEPSS 0.8%CVE-2023-23921Moodle: reflected xss risk in some returnurl parametersEPSS 0.8%CVE-2019-14831A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link coEPSS 0.8%CVE-2018-1045In Moodle 3.x, there is XSS via a calendar event name.EPSS 0.8%CVE-2023-35132MEDIUMMoodle: minor sql injection risk on mnet sso access control pageEPSS 0.8%CVE-2024-43436HIGHMoodle: site administration sql injection via xmldb editorEPSS 0.8%CVE-2021-32472Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.EPSS 0.8%