Release date:
Updated on:
Affected Systems:
Moodle 2.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0213
Moodle is a course Management System (CMS), also known as Learning Management System (LMS) or virtual learning environment (VLE ).
In versions earlier than Moodle 2.6.3, mod/assign/locallib in the Assignment subsystem. php has multiple cross-site Request Forgery vulnerabilities. Remote attackers can exploit this vulnerability to hijack teachers' quick and hierarchical request identity verification.
<* Source: Moodle
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Moodle
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://moodle.org/mod/forum/discuss.php? D = 260361
Http://git.moodle.org/gw? P = moodle. git & a = search & h = HEAD & st = commit & s = MDL-44606
This article permanently updates the link address: