Release date:
Updated on:
Affected Systems:
Moodle 2.5.x
Moodle 2.3.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0009, CVE-2014-0010
Moodle is a course Management System (CMS), also known as Learning Management System (LMS) or virtual learning environment (VLE ).
Moodle 2.3-2.3.10, 2.4-2.4.7, 2.5-2.5.4, and 2.6 have errors in the implementation of the login-as function, which can cause attackers to log on to another group of users; you can also perform some operations through HTTP requests without verifying these requests.
<* Source: Itamar Tzadok
Link: http://secunia.com/advisories/56556/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Moodle
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://moodle.org/
Https://moodle.org/mod/forum/discuss.php? D = 252415
Https://moodle.org/mod/forum/discuss.php? D = 252416