Moodle Multiple Vulnerabilities
Last Update Date:
20 May 2015 09:13
Release Date:
20 May 2015
3725
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities were idenitifed in Moodle. A remote authenticated user can obtain potentially sensitive information. A remote user can conduct cross-site scripting attacks and bypass security controls on the target system.
Impact
- Cross-Site Scripting
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Versions prior to 2.6.11, 2.7.8, 2.8.6, 2.9
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (2.6.11, 2.7.8, 2.8.6, 2.9).
Vulnerability Identifier
- CVE-2015-3174
- CVE-2015-3175
- CVE-2015-3176
- CVE-2015-3177
- CVE-2015-3178
- CVE-2015-3179
- CVE-2015-3180
- CVE-2015-3181
Source
Related Link
Share with