ALT-PU-2019-2248-1
Closed vulnerabilities
BDU:2020-02113
Уязвимость виртуальной обучающей среды moodle, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
Modified: 2024-11-21
CVE-2019-10186
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
- http://www.securityfocus.com/bid/109175
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10186
- https://moodle.org/mod/forum/discuss.php?d=388567#p1566329
- http://www.securityfocus.com/bid/109175
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10186
- https://moodle.org/mod/forum/discuss.php?d=388567#p1566329
Modified: 2024-11-21
CVE-2019-10187
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
- http://www.securityfocus.com/bid/109174
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10187
- https://moodle.org/mod/forum/discuss.php?d=388568#p1566330
- http://www.securityfocus.com/bid/109174
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10187
- https://moodle.org/mod/forum/discuss.php?d=388568#p1566330
Modified: 2024-11-21
CVE-2019-10188
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
Modified: 2024-11-21
CVE-2019-10189
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.