CVE-2014-0213: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allow remote attackers to hijack the authentication of teachers for quick-grading requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0213?
CVE-2014-0213 is classified as a high severity vulnerability due to its potential to allow remote attackers to hijack user sessions.
How do I fix CVE-2014-0213?
To fix CVE-2014-0213, upgrade to Moodle versions 2.4.10, 2.5.6, 2.6.3 or later.
What types of systems are affected by CVE-2014-0213?
CVE-2014-0213 affects multiple versions of Moodle from 2.0.0 up to 2.3.11 and certain 2.4.x, 2.5.x, and 2.6.x versions.
What specific function is compromised in CVE-2014-0213?
CVE-2014-0213 compromises the Assignment subsystem in Moodle, particularly through mod/assign/locallib.php.
Can CVE-2014-0213 be exploited through a phishing attack?
Yes, CVE-2014-0213 can be exploited through cross-site request forgery (CSRF), making phishing attacks a potential vector.