Skip to main content

Moodle Multiple Vulnerabilities

Last Update Date: 23 Sep 2015 Release Date: 22 Sep 2015 3118 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities have been identified in Moodle. A remote user can guess password recovery tokens to gain access to the target user account, delete files and access data on the target system, and conduct cross-site scripting attacks.


Impact

  • Cross-Site Scripting
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Prior to versions 2.7.10, 2.8.8, 2.9.2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (2.7.10, 2.8.8, 2.9.2).

Vulnerability Identifier


Source


Related Link