CVE-2014-3542

Moodle < 2.3.11, 2.4.x < 2.4.11, 2.5.x < 2.5.7, 2.6.x < 2.6.4, 2.7.x < 2.7.1 - XXE Injection via LTI

Title source: llm
STIX 2.1

Description

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/07/21/1
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=264263

Scores

EPSS 0.0043
EPSS Percentile 62.6%

Details

CWE
CWE-200
Status published
Products (36)
moodle/moodle 2.7.0
moodle/moodle 2.6.0
moodle/moodle 2.6.1
moodle/moodle 2.6.2
moodle/moodle 2.6.3
moodle/moodle 2.3.0
moodle/moodle 2.3.1
moodle/moodle 2.3.2
moodle/moodle 2.3.3
moodle/moodle 2.3.4
... and 26 more
Published Jul 29, 2014
Tracked Since Feb 18, 2026