Release date:
Updated on:
Affected Systems:
Moodle 2.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0218
Moodle is a course Management System (CMS), also known as Learning Management System (LMS) or virtual learning environment (VLE ).
Moodle 2.3.11, 2.4.10, 2.5.6, 2.6.3 or earlier, repository/url/lib. the URL download server inventory in php is a cross-site scripting vulnerability. Remote attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML.
<* Source: Moodle
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Moodle
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.moodle.org/gw? P = moodle. git & a = search & h = HEAD & st = commit & s = MDL-45332
Https://moodle.org/mod/forum/discuss.php? D = 260366
This article permanently updates the link address: