CVE-2014-3545: Code Injection
Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execute arbitrary code via a calculated question in a quiz.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3545?
CVE-2014-3545 is considered to have a high severity, allowing remote authenticated users to execute arbitrary code.
How do I fix CVE-2014-3545?
To fix CVE-2014-3545, upgrade to Moodle version 2.4.11, 2.5.7, 2.6.4, or 2.7.1 to mitigate the vulnerability.
What versions of Moodle are affected by CVE-2014-3545?
CVE-2014-3545 affects Moodle versions up to 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1.
Can CVE-2014-3545 be exploited by unauthenticated users?
No, CVE-2014-3545 requires attackers to be authenticated users to exploit the vulnerability.
What is the type of vulnerability for CVE-2014-3545?
CVE-2014-3545 is classified as a code execution vulnerability occurring in the context of calculated questions in quizzes.