CVE-2014-0010: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0010?
CVE-2014-0010 has a medium severity level as it allows remote attackers to hijack the authentication of administrators.
How do I fix CVE-2014-0010?
To fix CVE-2014-0010, upgrade Moodle to the latest version that addresses this vulnerability.
What versions are affected by CVE-2014-0010?
CVE-2014-0010 affects Moodle versions prior to 2.6.1, including 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and others.
What type of vulnerability is CVE-2014-0010?
CVE-2014-0010 is classified as a cross-site request forgery (CSRF) vulnerability.
Can CVE-2014-0010 be exploited remotely?
Yes, CVE-2014-0010 can be exploited remotely, allowing attackers to perform unauthorized actions on behalf of an administrator.