CVE-2014-0129: Medium severity Moodle moodle vulnerability
badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.5.5
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0129?
The severity of CVE-2014-0129 is rated as high due to the potential for exploitation by authenticated users to manipulate badge visibility.
How do I fix CVE-2014-0129?
To fix CVE-2014-0129, upgrade Moodle to version 2.5.5 or higher for the 2.5.x series, or to version 2.6.2 or higher for the 2.6.x series.
What versions of Moodle are affected by CVE-2014-0129?
CVE-2014-0129 affects Moodle versions prior to 2.5.5 for the 2.5.x series and 2.6.2 for the 2.6.x series.
What type of vulnerability is CVE-2014-0129?
CVE-2014-0129 is a security vulnerability that allows unauthorized modification of badge visibility by authenticated users.
Can CVE-2014-0129 be exploited remotely?
Yes, CVE-2014-0129 can be exploited by remote authenticated users who can alter badge visibility.