Permissions, Privileges, and Access Controls in Moodle - CVE-2014-0123

 

Permissions, Privileges, and Access Controls in Moodle - CVE-2014-0123

Published: March 24, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41893
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0123
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2014-0123

Install update from vendor's website.

moodle - update to 2.4.9-1.el6

External References

Related Security Bulletins