Exposición de Moodle

LMS
74
score de exposición
10.577
sitios usan
0
en explotación
8
críticos
Análisis Vexday

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 resultados
CVE-2021-20186It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of EPSS 0.8%CVE-2019-14829A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creatEPSS 0.7%CVE-2023-28336Moodle: teacher can access names of users they do not have permission to accessEPSS 0.7%CVE-2023-1402Moodle: course participation report shows roles the user should not seeEPSS 0.7%CVE-2021-32477The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capabilEPSS 0.7%CVE-2021-36395HIGHIn Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.EPSS 0.7%CVE-2022-0334A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capabiliEPSS 0.7%CVE-2021-20184It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meantEPSS 0.7%CVE-2024-43426HIGHMoodle: arbitrary file read risk through pdftexEPSS 0.7%CVE-2021-40691A session hijack risk was identified in the Shibboleth authentication plugin.EPSS 0.7%CVE-2019-14879MEDIUMA vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment waEPSS 0.7%CVE-2022-45150MEDIUMA reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied EPSS 0.7%CVE-2020-14320In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.EPSS 0.7%CVE-2016-8643In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.EPSS 0.7%CVE-2023-35131MEDIUMMoodle: xss risk on groups pageEPSS 0.7%CVE-2022-45151MEDIUMThe stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "socialEPSS 0.7%CVE-2019-14827A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contextsEPSS 0.7%CVE-2023-28331MEDIUMMoodle: xss risk when outputting database activity filter dataEPSS 0.7%CVE-2024-43440HIGHMoodle: lfi vulnerability when restoring malformed block backupsEPSS 0.6%CVE-2020-1754MEDIUMIn Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not EPSS 0.6%