CVE-2014-0122: Medium severity Moodle moodle vulnerability
mod/chat/chatajax.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly check for the mod/chat:chat capability during chat sessions, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by remaining in a chat session after an intra-session capability removal by an administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
Moodle mod/chatto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
Moodle mod/chatto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
Moodle mod/chatto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
Moodle mod/chatto a version that resolves this vulnerability.Fixed in 2.3.11
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0122?
CVE-2014-0122 has a high severity rating due to its capability to allow unauthorized access by authenticated users.
How do I fix CVE-2014-0122?
To fix CVE-2014-0122, upgrade Moodle to version 2.4.9, 2.5.5, or 2.6.2 or later.
Which versions of Moodle are affected by CVE-2014-0122?
CVE-2014-0122 affects Moodle versions up to 2.3.11 and multiple versions in the 2.4.x, 2.5.x, and 2.6.x series prior to their respective fixes.
What is the vulnerability in CVE-2014-0122?
CVE-2014-0122 is a vulnerability that fails to properly validate the mod/chat:chat capability, enabling a bypass of access restrictions.
Who can exploit CVE-2014-0122?
Remote authenticated users can exploit CVE-2014-0122 in opportunistic circumstances to gain unauthorized access to chat sessions.