First published: Tue Jul 29 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger an AJAX exception dialog.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=2.7.0<2.7.1 | 2.7.1 |
composer/moodle/moodle | >=2.6.0<2.6.4 | 2.6.4 |
composer/moodle/moodle | >=2.5.0<2.5.7 | 2.5.7 |
composer/moodle/moodle | <2.4.11 | 2.4.11 |
Moodle | <=2.3.11 | |
Moodle | =2.3.0 | |
Moodle | =2.3.1 | |
Moodle | =2.3.2 | |
Moodle | =2.3.3 | |
Moodle | =2.3.4 | |
Moodle | =2.3.5 | |
Moodle | =2.3.6 | |
Moodle | =2.3.7 | |
Moodle | =2.3.8 | |
Moodle | =2.3.9 | |
Moodle | =2.3.10 | |
Moodle | =2.4.0 | |
Moodle | =2.4.1 | |
Moodle | =2.4.2 | |
Moodle | =2.4.3 | |
Moodle | =2.4.4 | |
Moodle | =2.4.5 | |
Moodle | =2.4.6 | |
Moodle | =2.4.7 | |
Moodle | =2.4.8 | |
Moodle | =2.4.9 | |
Moodle | =2.4.10 | |
Moodle | =2.5.0 | |
Moodle | =2.5.1 | |
Moodle | =2.5.2 | |
Moodle | =2.5.3 | |
Moodle | =2.5.4 | |
Moodle | =2.5.5 | |
Moodle | =2.5.6 | |
Moodle | =2.6.0 | |
Moodle | =2.6.1 | |
Moodle | =2.6.2 | |
Moodle | =2.6.3 | |
Moodle | =2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3548 is classified as a medium severity vulnerability that allows remote attackers to perform cross-site scripting attacks.
To fix CVE-2014-3548, upgrade Moodle to version 2.4.11, 2.5.7, 2.6.4, or 2.7.1 or later.
CVE-2014-3548 enables remote attackers to inject arbitrary web scripts or HTML into the Moodle platform.
Moodle versions through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 are affected by CVE-2014-3548.
Yes, patches are available through upgrading to the specified secure versions of Moodle.