PT-2014-3484 · Moodle · Moodle

Published

2014-03-22

·

Updated

2022-05-13

·

CVE-2014-0123

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 2.3.11 and earlier, 2.4.x through 2.4.8, 2.5.x through 2.5.4, 2.6.x through 2.6.1
Description The wiki subsystem in Moodle does not properly restrict view and edit access. This allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.
Recommendations For versions 2.3.11 and earlier, update to version 2.3.12 or later. For versions 2.4.x through 2.4.8, update to version 2.4.9 or later. For versions 2.5.x through 2.5.4, update to version 2.5.5 or later. For versions 2.6.x through 2.6.1, update to version 2.6.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0123
GHSA-2VHR-4MHQ-M35C
MGASA-2014-0160

Affected Products

Moodle