CVE-2014-0126

Moodle < 2.3.11, 2.4.x < 2.4.9, 2.5.x < 2.5.5, 2.6.x < 2.6.2 - Cross-Site Request Forgery via IMS Enterprise File Import

Title source: llm
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=256423
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/03/17/1

Scores

EPSS 0.0013
EPSS Percentile 31.3%

Details

CWE
CWE-352
Status published
Products (50)
moodle/moodle 2.0.0
moodle/moodle 2.0.1
moodle/moodle 2.0.2
moodle/moodle 2.0.3
moodle/moodle 2.0.4
moodle/moodle 2.0.5
moodle/moodle 2.0.6
moodle/moodle 2.0.7
moodle/moodle 2.0.8
moodle/moodle 2.0.9
... and 40 more
Published Mar 24, 2014
Tracked Since Feb 18, 2026