Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Moodle 2.7.x < 2.7.1 XSS

Medium

Synopsis

The remote web server is hosting a web application that is vulnerable to multiple stored cross-site scripting (XSS) attacks.

Description

The remote web server hosts Moodle, an open-source course management system. Versions of Moodle 2.7.x prior to 2.7.1 are exposed to the following vulnerabilities :

- A cross-site scripting vulnerability affects the 'failed login' logs. Log entries of failed login attempts were not filtered correctly. (MSA-14-0030 / CVE-2014-3549)

- A cross-site scripting vulnerability affects error messages generated by scheduled tasks were being presented to admins without correct filtering. (MSA-14-0031 / CVE-2014-3550)

Solution

Upgrade to Moodle version 2.7.1 or later.