CVE-2014-3550: XSS
Multiple cross-site scripting (XSS) vulnerabilities in admin/tool/task/scheduledtasks.php in Moodle 2.7.x before 2.7.1 allow remote attackers to inject arbitrary web script or HTML via vectors that trigger a crafted (1) error or (2) success message for a scheduled task.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3550?
The severity of CVE-2014-3550 is rated as high due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-3550?
To fix CVE-2014-3550, update Moodle to version 2.7.1 or later, where the vulnerabilities have been patched.
Which versions of Moodle are affected by CVE-2014-3550?
CVE-2014-3550 affects Moodle version 2.7.0 and earlier.
What types of attacks can CVE-2014-3550 be exploited for?
CVE-2014-3550 can be exploited for cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary scripts or HTML.
Who can exploit CVE-2014-3550?
CVE-2014-3550 can be exploited by remote attackers who can trigger specific error or success messages in scheduled tasks.