CVE-2014-3548: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger an AJAX exception dialog.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3548?
CVE-2014-3548 is classified as a medium severity vulnerability that allows remote attackers to perform cross-site scripting attacks.
How do I fix CVE-2014-3548?
To fix CVE-2014-3548, upgrade Moodle to version 2.4.11, 2.5.7, 2.6.4, or 2.7.1 or later.
What kind of attack does CVE-2014-3548 enable?
CVE-2014-3548 enables remote attackers to inject arbitrary web scripts or HTML into the Moodle platform.
Which versions of Moodle are affected by CVE-2014-3548?
Moodle versions through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 are affected by CVE-2014-3548.
Is there a patch available for CVE-2014-3548?
Yes, patches are available through upgrading to the specified secure versions of Moodle.