CVE-2014-0218: XSS
Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0218?
CVE-2014-0218 is classified as a medium severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2014-0218?
To fix CVE-2014-0218, upgrade your Moodle installation to version 2.6.3 or later, 2.5.6 or later, or 2.4.10 or later.
Which versions of Moodle are affected by CVE-2014-0218?
CVE-2014-0218 affects Moodle versions through 2.3.11, and all versions before 2.4.10, 2.5.6, and 2.6.3.
What kind of attack does CVE-2014-0218 enable?
CVE-2014-0218 allows remote attackers to inject arbitrary web scripts or HTML via unspecified methods.
Is there a patch available for CVE-2014-0218?
Yes, patches are available by upgrading to the specified remedial versions of Moodle.