CVE-2014-3552: Medium severity moodle vulnerability
The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3552?
CVE-2014-3552 has a medium severity rating due to the potential for session hijacking by authenticated users.
How do I fix CVE-2014-3552?
To fix CVE-2014-3552, update your Moodle installation to version 2.4.11, 2.5.7, or later.
Which Moodle versions are affected by CVE-2014-3552?
CVE-2014-3552 affects Moodle versions up to and including 2.3.11, all 2.4.x versions before 2.4.11, and all 2.5.x versions before 2.5.7.
Can CVE-2014-3552 be exploited remotely?
Yes, CVE-2014-3552 can be exploited remotely by authenticated users who interact with the plugin.
What impact does CVE-2014-3552 have on user sessions?
CVE-2014-3552 allows attackers to hijack user sessions by taking advantage of an unverified session ID.