Code Injection in Moodle - CVE-2013-5674

 

Code Injection in Moodle - CVE-2013-5674

Published: September 16, 2013 / Updated: August 10, 2020


Vulnerability identifier: #VU42569
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-5674
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.


Affected software

Moodle

How to mitigate CVE-2013-5674

Install update from vendor's website.


External References

Related Security Bulletins