CVE-2014-3542: Infoleak
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3542?
CVE-2014-3542 has a medium severity rating due to its potential for unauthorized file access.
How do I fix CVE-2014-3542?
To fix CVE-2014-3542, upgrade Moodle to version 2.7.1 or later, or patch affected versions as recommended.
Which versions of Moodle are affected by CVE-2014-3542?
CVE-2014-3542 affects Moodle versions up to 2.3.11 and from 2.4.0 to 2.4.10, 2.5.0 to 2.5.6, and 2.6.0 to 2.6.3.
Can CVE-2014-3542 be exploited remotely?
Yes, CVE-2014-3542 can be exploited remotely by attackers to read arbitrary files on the server.
What type of vulnerability is CVE-2014-3542 classified as?
CVE-2014-3542 is classified as an XML External Entity (XXE) vulnerability.