First published: Tue Jul 29 2014(Updated: )
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=2.7.0<2.7.1 | 2.7.1 |
composer/moodle/moodle | >=2.6.0<2.6.4 | 2.6.4 |
composer/moodle/moodle | >=2.5.0<2.5.7 | 2.5.7 |
composer/moodle/moodle | <2.4.11 | 2.4.11 |
Moodle | =2.4.0 | |
Moodle | =2.4.1 | |
Moodle | =2.4.2 | |
Moodle | =2.4.3 | |
Moodle | =2.4.4 | |
Moodle | =2.4.5 | |
Moodle | =2.4.6 | |
Moodle | =2.4.7 | |
Moodle | =2.4.8 | |
Moodle | =2.4.9 | |
Moodle | =2.4.10 | |
Moodle | <=2.3.11 | |
Moodle | =2.3.0 | |
Moodle | =2.3.1 | |
Moodle | =2.3.2 | |
Moodle | =2.3.3 | |
Moodle | =2.3.4 | |
Moodle | =2.3.5 | |
Moodle | =2.3.6 | |
Moodle | =2.3.7 | |
Moodle | =2.3.8 | |
Moodle | =2.3.9 | |
Moodle | =2.3.10 | |
Moodle | =2.6.0 | |
Moodle | =2.6.1 | |
Moodle | =2.6.2 | |
Moodle | =2.6.3 | |
Moodle | =2.7.0 | |
Moodle | =2.5.0 | |
Moodle | =2.5.1 | |
Moodle | =2.5.2 | |
Moodle | =2.5.3 | |
Moodle | =2.5.4 | |
Moodle | =2.5.5 | |
Moodle | =2.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3544 is considered to be medium due to its impact on web application security.
To fix CVE-2014-3544, upgrade to Moodle version 2.7.1 or later, or apply patches provided in the Moodle security releases.
CVE-2014-3544 affects Moodle versions 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1.
CVE-2014-3544 is classified as a cross-site scripting (XSS) vulnerability.
Yes, remote authenticated users can exploit CVE-2014-3544 to inject arbitrary web scripts or HTML through the Skype ID profile field.