CVE-2014-0214: Medium severity Moodle moodle vulnerability
login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token with an infinite lifetime, which makes it easier for remote attackers to hijack sessions via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0214?
CVE-2014-0214 is considered a high severity vulnerability, allowing for potential session hijacking.
How do I fix CVE-2014-0214?
To fix CVE-2014-0214, upgrade your Moodle installation to version 2.6.3, 2.5.6, or 2.4.10 or later.
What versions of Moodle are affected by CVE-2014-0214?
CVE-2014-0214 affects Moodle versions 2.3.x through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3.
Can a remote attacker exploit CVE-2014-0214?
Yes, a remote attacker can exploit CVE-2014-0214 through brute-force attacks due to the infinite lifetime of the web-service token.
What is the impact of CVE-2014-0214 on Moodle users?
The impact of CVE-2014-0214 on Moodle users includes the potential for session hijacking, compromising user accounts and sensitive data.