Moodle 2.6.x < 2.6.6 / 2.7.x < 2.7.3 Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 8720

Synopsis

The remote web server is hosting a web application that is vulnerable to multiple attack vectors.

Description

The remote web server hosts Moodle, an open-source course management system. Versions of Moodle 2.6.x prior to 2.6.6, or 2.7.x prior to 2.7.3 are exposed to the following vulnerabilities :

- A security bypass flaw exists in 'mod/forum/externallib.php' because it does not verify group permissions. This could allow remote authenticated users to access any forum via the 'forum_get_discussions' web service. (MSA-14-0043 / CVE-2014-7834)

- An information disclosure flaw exists in 'lib/phpunit/bootstrap.php'. By directly accessing an internal file, an unauthenticated user can be shown an error message containing the file system path of the Moodle install. (MSA-14-0044 / CVE-2014-7848)

- A cross-site scripting (XSS) vulnerability exists in the profile picture area. An authenticated user could upload a file which contains malicious JavaScript as their profile picture to attack any users which access the affected profile. (MSA-14-0045 / CVE-2014-7835)

Solution

Upgrade to Moodle version 2.7.3. If your installation cannot be upgraded to 2.7.x, version 2.6.6 is also patched for these vulnerabilities.

See Also

http://moodle.org/security

http://www.nessus.org/u?e73e48cd

https://moodle.org/mod/forum/discuss.php?d=275159

https://moodle.org/mod/forum/discuss.php?d=275160

https://moodle.org/mod/forum/discuss.php?d=275161

Plugin Details

Severity: Medium

ID: 8720

Family: CGI

Published: 2015/04/20

Modified: 2016/01/21

Dependencies: 8690

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 5

Temporal Score: 4.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

CVSSv3

Base Score: 5.3

Temporal Score: 5.1

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS3#E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:moodle:moodle

Patch Publication Date: 2014/11/10

Vulnerability Publication Date: 2014/11/17

Reference Information

CVE: CVE-2014-7834, CVE-2014-7835, CVE-2014-7848

BID: 71126, 71127, 71129