CVE-2014-0127: Medium severity Moodle moodle vulnerability
The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/completeguest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 2.4.9 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Compensating control
As a mitigating step until the Moodle upgrade, restrict remote authenticated users’ ability to start Feedback activities (e.g., via role/permission controls for the Feedback activity module) so they cannot exploit the time-validation bypass in mod/feedback/complete.php and mod/feedback/complete_guest.php.
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0127?
CVE-2014-0127 has a moderate severity rating, allowing remote authenticated users to bypass restrictions on starting a Feedback activity.
How do I fix CVE-2014-0127?
To fix CVE-2014-0127, upgrade to Moodle versions 2.4.9, 2.5.5, or 2.6.2 or later.
Which versions of Moodle are affected by CVE-2014-0127?
CVE-2014-0127 affects Moodle versions prior to 2.4.9, 2.5.5, and 2.6.2.
What is the nature of the vulnerability in CVE-2014-0127?
CVE-2014-0127 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity.
When was CVE-2014-0127 published?
CVE-2014-0127 was published in March 2014.