CVE-2014-7836: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/requesttool.php or (2) mod/lti/instructoredittooltype.php request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7836?
CVE-2014-7836 is classified as a moderate severity vulnerability due to its nature of enabling cross-site request forgery attacks.
How do I fix CVE-2014-7836?
To fix CVE-2014-7836, upgrade Moodle to at least version 2.5.9, 2.6.6, or 2.7.3 depending on your current version.
What versions of Moodle are affected by CVE-2014-7836?
CVE-2014-7836 affects Moodle versions 2.4.11 and earlier, as well as 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3.
What type of vulnerabilities does CVE-2014-7836 represent?
CVE-2014-7836 represents multiple cross-site request forgery (CSRF) vulnerabilities.
Can CVE-2014-7836 allow unauthorized access to user accounts?
Yes, CVE-2014-7836 can allow remote attackers to hijack the authentication of arbitrary users.