CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

CVE-2017-2641 Moodle Multiple Security Vulnerabilities (MDL-58010,MDL-56526,MDL-57596,MDL-57597)

2017年4月12日 1509点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

Moodle (Modular Object-Oriented Dynamic Learning Environment) is a free e-learning software platform, also known as a Learning Management System, or Virtual Learning Environment.

The following vulnerabilities have been confirmed in Moodle:
CVE-2017-2641: PoC was presented of SQL injection by an ordinary registered user on Moodle 3.2 via web interface. Similar scenario could be used in previous versions of Moodle but only by managers/admins and only via web services.
CVE-2017-2643: Global search does not respect "Force login for profiles" setting and displays user names to guests when it should not (User profiles were still not displayed)
CVE-2017-2644: Registered user could submit evidence of prior learning that includes XSS that will be executed for another user who tried to edit the same evidence
CVE-2017-2645: Serving files attached to evidence of prior learning did not force download. When viewed by other users they would be opened in current moodle sessions

Affected Versions:
Moodle 3.2 to 3.2.1, 3.1 to 3.1.4, 3.0 to 3.0.8, 2.7.0 to 2.7.18 and earlier unsupported versions.

漏洞危害

Depending on the vulnerability being exploited, a remote attacker could conduct cross-site scripting or SQL injection attacks against a targeted server.

解决方案

Customers are advised to upgrade to the latest version of the software available. The latest version can be downloaded fromhere.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

Moodle 3.2.2, 3.1.5, 3.0.9, 2.7.19 or later

0day

标签: 暂无
最后更新:2017年4月12日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me