CVE-2014-0123 PUBLISHED CVSS 4.900000095367432 MEDIUM

The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.

EPSS 0.19% · 41.1th percentile

Risk Scores

CVSS v2.0
4.900000095367432
EPSS Score
0.19%
41.1th percentile

Affected Products

VendorProductVersions
moodlemoodle0, 2.5.0, 2.6.0
moodlemoodle2.0.1, 2.0.2, 2.0.3
n/an/a*

Timeline

References

Open in Interactive Console →