CVE-2014-3544: XSS
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3544?
The severity of CVE-2014-3544 is considered to be medium due to its impact on web application security.
How do I fix CVE-2014-3544?
To fix CVE-2014-3544, upgrade to Moodle version 2.7.1 or later, or apply patches provided in the Moodle security releases.
What versions of Moodle are affected by CVE-2014-3544?
CVE-2014-3544 affects Moodle versions 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1.
What type of vulnerability is CVE-2014-3544?
CVE-2014-3544 is classified as a cross-site scripting (XSS) vulnerability.
Can remote authenticated users exploit CVE-2014-3544?
Yes, remote authenticated users can exploit CVE-2014-3544 to inject arbitrary web scripts or HTML through the Skype ID profile field.