CVE-2014-2571: XSS
Cross-site scripting (XSS) vulnerability in the quizquestiontostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.6.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.5.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.4.9
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2571?
CVE-2014-2571 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-2571?
To fix CVE-2014-2571, update Moodle to version 2.4.9, 2.5.5, or 2.6.2 or later.
Who is affected by CVE-2014-2571?
CVE-2014-2571 affects all versions of Moodle from 2.0.0 through 2.6.1, allowing remote authenticated users to exploit the vulnerability.
What type of vulnerability is CVE-2014-2571?
CVE-2014-2571 is a Cross-Site Scripting (XSS) vulnerability, allowing attackers to inject arbitrary web scripts or HTML.
Can I still use older versions of Moodle if I have CVE-2014-2571?
Using older versions of Moodle that are affected by CVE-2014-2571 poses a security risk and is not recommended.