Release date:
Updated on:
Affected Systems:
Moodle 2.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0217
Moodle is a course Management System (CMS), also known as Learning Management System (LMS) or virtual learning environment (VLE ).
Enrol/index in versions earlier than Moodle 2.6.3. php does not check the moodle/course: viewhiddencourses function before listing hidden courses. This allows remote attackers to exploit the client role and specially crafted URL to obtain sensitive information and abstract information.
<* Source: Moodle
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Moodle
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://moodle.org/mod/forum/discuss.php? D = 260365
Http://git.moodle.org/gw? P = moodle. git & a = search & h = HEAD & st = commit & s = MDL-45126
This article permanently updates the link address: