CVE-2014-0215: Infoleak
The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0215?
CVE-2014-0215 has a medium severity rating due to the potential for remote authenticated users to de-anonymize student identities.
How do I fix CVE-2014-0215?
To mitigate CVE-2014-0215, upgrade your Moodle installation to version 2.4.10, 2.5.6, or 2.6.3 or later.
Which versions are affected by CVE-2014-0215?
CVE-2014-0215 affects Moodle versions up to and including 2.4.9, 2.5.5, and 2.6.2.
Who can exploit CVE-2014-0215?
CVE-2014-0215 can be exploited by remote authenticated users who can utilize screen readers or read the HTML source.
Is CVE-2014-0215 still a concern today?
While CVE-2014-0215 has been patched in later versions of Moodle, systems on older versions remain vulnerable.