Moodle是Moodle开源的一套免费的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 Moodle存在安全漏洞,该漏洞源于未在查看或删除Feedback活动响应时正确考虑分组模式的权限检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Moodle Project | moodle | 4.5.0 ~ 4.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-26525 | 8.6 HIGH | Arbitrary file read risk through pdfTeX |
| CVE-2025-26530 | 8.3 HIGH | Reflected XSS via question bank filter |
| CVE-2025-26529 | 8.3 HIGH | Stored XSS risk in admin live log |
| CVE-2025-26533 | 8.1 HIGH | SQL injection risk in course search module list filter |
| CVE-2025-26527 | 5.3 MEDIUM | Non-searchable tags can still be discovered on the tag search page and in the tags block |
| CVE-2025-26528 | 3.4 LOW | Stored XSS in ddimageortext question type |
| CVE-2025-26532 | 3.1 LOW | Teachers can evade trusttext config when restoring glossary entries |
| CVE-2025-26531 | 3.1 LOW | IDOR in badges allows disabling of arbitrary badges |
No comments yet