The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-39990 - | |
References | () http://openwall.com/lists/oss-security/2014/03/17/1 - | |
References | () https://moodle.org/mod/forum/discuss.php?d=256419 - Vendor Advisory |
Information
Published : 2014-03-24 14:20
Updated : 2024-11-21 02:01
NVD link : CVE-2014-0123
Mitre link : CVE-2014-0123
CVE.ORG link : CVE-2014-0123
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-264
Permissions, Privileges, and Access Controls