CVE-2014-3551: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3551?
CVE-2014-3551 is classified as a medium-severity vulnerability that allows cross-site scripting (XSS) attacks.
How do I fix CVE-2014-3551?
To mitigate CVE-2014-3551, upgrade Moodle to version 2.5.7, 2.6.4, or 2.7.1 or later.
Which versions of Moodle are affected by CVE-2014-3551?
CVE-2014-3551 affects Moodle versions 2.3.0 to 2.3.11, 2.4.0 to 2.4.10, 2.5.0 to 2.5.6, 2.6.0 to 2.6.3, and 2.7.0.
Can CVE-2014-3551 be exploited by remote attackers?
Yes, CVE-2014-3551 can be exploited by remote authenticated users to inject arbitrary web scripts or HTML.
What types of attacks can be performed using CVE-2014-3551?
CVE-2014-3551 can allow attackers to perform XSS attacks, potentially compromising the security of user sessions and data.