CVE-2014-0124: Medium severity Moodle moodle vulnerability
The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/overrideform.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
Moodle mod/forum/renderer.phpto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
Moodle mod/quiz/override_form.phpto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 2.6.2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0124?
CVE-2014-0124 is classified as a medium-severity vulnerability.
How do I fix CVE-2014-0124?
To fix CVE-2014-0124, you should upgrade to Moodle version 2.6.2, 2.5.5, or 2.4.9.
Which versions of Moodle are affected by CVE-2014-0124?
CVE-2014-0124 affects Moodle versions prior to 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2.
What kind of information can be exposed due to CVE-2014-0124?
CVE-2014-0124 can lead to unauthorized display of email addresses of users.
What are the consequences of not addressing CVE-2014-0124?
Failure to address CVE-2014-0124 could result in privacy breaches and unauthorized access to sensitive user information.