CVE-2014-0216: Medium severity Moodle moodle vulnerability
The My Home implementation in the blockhtmlpluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0216?
CVE-2014-0216 is considered a medium severity vulnerability due to improper file access restrictions in Moodle.
How do I fix CVE-2014-0216?
To resolve CVE-2014-0216, upgrade Moodle to version 2.4.10 or higher, 2.5.6 or higher, or 2.6.3 or higher.
What versions of Moodle are affected by CVE-2014-0216?
CVE-2014-0216 affects Moodle versions 2.3.11 and earlier, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3.
What type of vulnerability is CVE-2014-0216?
CVE-2014-0216 is classified as an information disclosure vulnerability.
Can I check if my Moodle version is vulnerable to CVE-2014-0216?
You can check if your Moodle version is vulnerable to CVE-2014-0216 by comparing your version against the affected versions listed in its description.