SB2017012014 - Multiple vulnerabilities in Moodle



SB2017012014 - Multiple vulnerabilities in Moodle

Published: January 20, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017012014
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2016-5012)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

In Moodle 3.x, glossary search displays entries without checking user permissions to view them.


2) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2016-5013)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.


3) Information disclosure (CVE-ID: CVE-2016-5014)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.


Remediation

Install update from vendor's website.