SB2014012202 - Fedora EPEL 6 update for moodle



SB2014012202 - Fedora EPEL 6 update for moodle

Published: January 22, 2014 Updated: April 24, 2025

Security Bulletin ID SB2014012202
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Credentials management (CVE-ID: CVE-2014-0008)

The vulnerability allows a remote #AU# to gain access to sensitive information.

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.


2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-0009)

The vulnerability allows a remote #AU# to read and manipulate data.

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.


3) Cross-site request forgery (CVE-ID: CVE-2014-0010)

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Remediation

Install update from vendor's website.