Lucene search

K
nessusTenable8719.PRM
HistoryApr 20, 2015 - 12:00 a.m.

Moodle < 2.5 / 2.5.x < 2.5.8 / 2.6.x < 2.6.5 / 2.7.x < 2.7.2 Multiple Vulnerabilities

2015-04-2000:00:00
Tenable
www.tenable.com
18

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.024

Percentile

90.0%

The remote web server hosts Moodle, an open-source course management system. Versions of Moodle 2.5.x prior to 2.5.8, 2.6.x prior to 2.6.5, 2.7.x prior to 2.7.2, and all previous releases are exposed to the following vulnerabilities :

  • A security bypass vulnerability affects the third-party library utilized by Moodle, phpCAS. Specifically, this is a flaw related to improper URL encoding in the back-channel ticket validation. With a specially crafted request, a remote attacker can bypass intended security constraints. (MSA-14-0033 / CVE-2014-4172)

  • An information disclosure vulnerability affects the Q&A forum. Specifically, this affects the script ‘/mod/forum/view.php’ by allowing users who had not yet posted the required answer to see the name of the last person who had posted their answer. (MSA-14-0034 / CVE-2014-3617)

Binary data 8719.prm

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.024

Percentile

90.0%