Moodle是一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。Shibboleth是英国Shibboleth公司的一套基于Windows平台的开源的SAML协议的Web单点登录系统。 Moodle 存在授权问题漏洞,该漏洞源于Shibboleth认证插件的会话劫持风险。远程攻击者可利用该漏洞获取系统的敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | moodle | 3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23664 | 8.6 HIGH | Server-side Request Forgery (SSRF) |
| CVE-2021-23460 | 7.5 HIGH | Prototype Pollution |
| CVE-2021-23631 | 7.5 HIGH | Directory Traversal |
| CVE-2021-23518 | 7.3 HIGH | Prototype Pollution |
| CVE-2021-46238 | GPAC 缓冲区错误漏洞 | |
| CVE-2021-46242 | HDF5 资源管理错误漏洞 | |
| CVE-2021-46244 | HDF5 数字错误漏洞 | |
| CVE-2021-39480 | Bingrep 安全漏洞 | |
| CVE-2022-23363 | g33kyrash Online Banking System SQL注入漏洞 | |
| CVE-2022-23364 | kabirkhyrul Hospital Managment System SQL注入漏洞 | |
| CVE-2022-23365 | kabirkhyrul Hospital Managment System SQL注入漏洞 | |
| CVE-2022-23366 | kabirkhyrul Hospital Managment System SQL注入漏洞 | |
| CVE-2021-46313 | GPAC 安全漏洞 | |
| CVE-2021-46239 | GPAC 资源管理错误漏洞 | |
| CVE-2021-46240 | GPAC 代码问题漏洞 | |
| CVE-2021-46237 | GPAC 代码问题漏洞 | |
| CVE-2021-46236 | GPAC 代码问题漏洞 | |
| CVE-2021-46234 | GPAC 代码问题漏洞 | |
| CVE-2021-40595 | Sourcecodester Online Leave Management System SQL注入漏洞 | |
| CVE-2021-40247 | Sourcecodester Budget And Expense Tracker System SQL注入漏洞 |
Showing top 20 of 47 CVEs. View all on vendor page → →
No comments yet