Moodle是一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 Moodle存在输入验证错误漏洞,该漏洞由于在处理包含HTML的电子邮件通知时,对用户提供的输入验证不足。在某些情况下,电子邮件的消息通知可能含有以HTML隐藏的原始消息的链接,这可能构成网络钓鱼的风险。受影响的产品及版本如下:Moodle: 3.9.0、3.9.1、3.9.2、3.9.3、3.9.4、3.9.5、3.9.6、3.9.7、3.10.0、3.10.1、3.10.2、3.10.3、3.10.4、3.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Moodle | 3.11, 3.10 to 3.10.4, 3.9 to 3.9.7 and earlier unsupported versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-26111 | 7.5 HIGH | node-static 路径遍历漏洞 |
| CVE-2023-26106 | 7.5 HIGH | dot-lens 安全漏洞 |
| CVE-2023-26107 | 6.9 MEDIUM | SketchSVG 代码注入漏洞 |
| CVE-2008-10004 | 6.3 MEDIUM | Email Registration email_registration.module email_registration_user sql injection |
| CVE-2023-1191 | 4.7 MEDIUM | fastcms ZIP File TemplateController.java path traversal |
| CVE-2023-1185 | 4.7 MEDIUM | ECshop New Product unrestricted upload |
| CVE-2023-1184 | 4.7 MEDIUM | ECshop Backup Database database.php unrestricted upload |
| CVE-2023-26108 | 3.7 LOW | nestjs 安全漏洞 |
| CVE-2022-4929 | 3.5 LOW | icplayer tts-utils.js cross site scripting |
| CVE-2022-4928 | 3.5 LOW | icplayer presenter.js AddonText_Selection_create cross site scripting |
| CVE-2015-10095 | 3.5 LOW | woo-popup Plugin class-woo-popup-admin.php cross site scripting |
| CVE-2015-10092 | 3.5 LOW | Qtranslate Slug Plugin class-qtranslate-slug.php add_slug_meta_box cross site scripting |
| CVE-2015-10093 | 2.6 LOW | Mark User as Spammer Plugin plugin.php user_row_actions cross site scripting |
| CVE-2015-10094 | 2.4 LOW | Fastly Plugin api.php post cross site scripting |
| CVE-2023-24735 | PMB 输入验证错误漏洞 | |
| CVE-2023-24736 | PMB 安全漏洞 | |
| CVE-2023-24737 | PMB 跨站脚本漏洞 | |
| CVE-2023-24763 | PrestaShop SQL注入漏洞 | |
| CVE-2023-24733 | PMB 跨站脚本漏洞 | |
| CVE-2023-24776 | Funadmin 安全漏洞 |
Showing top 20 of 56 CVEs. View all on vendor page → →
No comments yet