Moodle Multiple Vulnerabilities
Last Update Date:
23 Sep 2015
Release Date:
22 Sep 2015
3874
Views
RISK: Medium Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities have been identified in Moodle. A remote user can guess password recovery tokens to gain access to the target user account, delete files and access data on the target system, and conduct cross-site scripting attacks.
Impact
- Cross-Site Scripting
- Remote Code Execution
- Information Disclosure
- Data Manipulation
System / Technologies affected
- Prior to versions 2.7.10, 2.8.8, 2.9.2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (2.7.10, 2.8.8, 2.9.2).
Vulnerability Identifier
Source
Related Link
Share with