PT-2014-3484 · Moodle · Moodle

Publicado

2014-03-22

·

Atualizado

2022-05-13

·

CVE-2014-0123

CVSS v2.0

4.9

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 2.3.11 and earlier, 2.4.x through 2.4.8, 2.5.x through 2.5.4, 2.6.x through 2.6.1
Description The wiki subsystem in Moodle does not properly restrict view and edit access. This allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.
Recommendations For versions 2.3.11 and earlier, update to version 2.3.12 or later. For versions 2.4.x through 2.4.8, update to version 2.4.9 or later. For versions 2.5.x through 2.5.4, update to version 2.5.5 or later. For versions 2.6.x through 2.6.1, update to version 2.6.2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0123
GHSA-2VHR-4MHQ-M35C
MGASA-2014-0160

Produtos afetados

Moodle