CVE-2014-0126: CSRF
Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.4.9
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0126?
CVE-2014-0126 has a medium severity due to its potential to allow CSRF attacks on Moodle administrators.
How do I fix CVE-2014-0126?
To fix CVE-2014-0126, upgrade Moodle to version 2.6.2 or later, or to 2.5.5 or later, or to 2.4.9 or later.
What versions of Moodle are affected by CVE-2014-0126?
CVE-2014-0126 affects Moodle versions 2.3.11 and below, as well as versions 2.4.x prior to 2.4.9, 2.5.x prior to 2.5.5, and 2.6.x prior to 2.6.2.
What type of vulnerability is CVE-2014-0126?
CVE-2014-0126 is a cross-site request forgery (CSRF) vulnerability.
Can CVE-2014-0126 allow unauthorized access?
Yes, CVE-2014-0126 can allow remote attackers to hijack the authentication of administrators in Moodle.