Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian Lenny: DSA-2115-1 Notice: Moodle Remote Vulnerability Alert

debian
Calendar Grey September 29, 2010
Debian Logo
Multiple security flaws identified in Moodle software; it is strongly recommended to update for improved protection and risk minimization.
Several remote vulnerabilities have been discovered in Moodle, a course management system

Summary

Several remote vulnerabilities have been discovered in Moodle, a
course management system. The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2010-1613
Moodle does not enable the "Regenerate session id during
login" setting by default, which makes it easier for remote
attackers to conduct session fixation attacks.

CVE-2010-1614
Multiple cross-site scripting (XSS) vulnerabilities allow
remote attackers to inject arbitrary web script or HTML via
vectors related to (1) the Login-As feature or (2) when the
global search feature is enabled, unspecified global search
forms in the Global Search Engine.

CVE-2010-1615
Multiple SQL injection vulnerabilities allow remote attackers to execute arbitrary SQL commands via vectors related to (1)
the add_to_log function in mod/wiki/view.php in the wiki
module, or (2) "data validation in some forms elements"
related to lib/form/selectgroups.php.

CVE-2010-1616
Moodle can create new roles when restoring a course, which
a...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: moodle

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here