{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Moodle versions 1.7.x ant\u00e9rieures \u00e0 1.7.7.","product":{"name":"Moodle","vendor":{"name":"Moodle","scada":false}}},{"description":"Moodle versions 1.9.x ant\u00e9rieures \u00e0 1.9.4 ;","product":{"name":"Moodle","vendor":{"name":"Moodle","scada":false}}},{"description":"Moodle versions 1.8.x ant\u00e9rieures \u00e0 1.8.8 ;","product":{"name":"Moodle","vendor":{"name":"Moodle","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nPlusieurs vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans la derni\u00e8re version de\nMoodle. Elles permettent, entre autre, de mener des injections de code\nindirecte, des injection de requ\u00eates ill\u00e9gitimes par rebond, d'effacer\narbitrairement des fichiers.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2008-4796","url":"https://www.cve.org/CVERecord?id=CVE-2008-4796"},{"name":"CVE-2008-5153","url":"https://www.cve.org/CVERecord?id=CVE-2008-5153"}],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 de Moodle du 10 f\u00e9vrier 2009 :","url":"http://moodle.org/security/"}],"reference":"CERTA-2009-AVI-070","revisions":[{"description":"version initiale.","revision_date":"2009-02-13T00:00:00.000000"}],"risks":[{"description":"Injection de code indirecte \u00e0 distance (XSS)"},{"description":"Injection de requ\u00eates ill\u00e9gitimes par rebond (CSRF)"},{"description":"Atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"}],"summary":"Plusieurs vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans la derni\u00e8re version de\n<span class=\"textit\">Moodle</span>.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans Moodle","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Moodle du 10 f\u00e9vrier 2009","url":null}]}
