CVE-2014-0123: Medium severity Moodle moodle vulnerability
The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.5.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.6.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.3.11
Event History
Frequently Asked Questions
What are the affected versions for CVE-2014-0123?
The affected versions include Moodle 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2.
What is the vulnerability type of CVE-2014-0123?
CVE-2014-0123 is a wiki subsystem access control vulnerability in Moodle.
What is the severity of CVE-2014-0123?
CVE-2014-0123 has a medium severity as it allows unauthorized access to edit and view wiki pages.
How do I fix CVE-2014-0123?
To fix CVE-2014-0123, update your Moodle installation to 2.6.2, 2.5.5, or 2.4.9.
Who is impacted by CVE-2014-0123?
Remote authenticated users with the student role can exploit CVE-2014-0123 to perform unauthorized wiki operations.