SB2014012003 - Multiple vulnerabilities in Moodle



SB2014012003 - Multiple vulnerabilities in Moodle

Published: January 20, 2014 Updated: August 10, 2020

Security Bulletin ID SB2014012003
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-0009)

The vulnerability allows a remote #AU# to read and manipulate data.

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.


2) Credentials management (CVE-ID: CVE-2014-0008)

The vulnerability allows a remote #AU# to gain access to sensitive information.

lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.


Remediation

Install update from vendor's website.