5.8

CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

Data is provided by the National Vulnerability Database (NVD)
MoodleMoodle Version <= 2.3.11
MoodleMoodle Version2.0.0
MoodleMoodle Version2.0.1
MoodleMoodle Version2.0.2
MoodleMoodle Version2.0.3
MoodleMoodle Version2.0.4
MoodleMoodle Version2.0.5
MoodleMoodle Version2.0.6
MoodleMoodle Version2.0.7
MoodleMoodle Version2.0.8
MoodleMoodle Version2.0.9
MoodleMoodle Version2.1.0
MoodleMoodle Version2.1.1
MoodleMoodle Version2.1.2
MoodleMoodle Version2.1.3
MoodleMoodle Version2.1.4
MoodleMoodle Version2.1.5
MoodleMoodle Version2.1.6
MoodleMoodle Version2.1.7
MoodleMoodle Version2.1.8
MoodleMoodle Version2.1.9
MoodleMoodle Version2.1.10
MoodleMoodle Version2.2.0
MoodleMoodle Version2.2.1
MoodleMoodle Version2.2.2
MoodleMoodle Version2.2.3
MoodleMoodle Version2.2.4
MoodleMoodle Version2.2.5
MoodleMoodle Version2.2.6
MoodleMoodle Version2.2.7
MoodleMoodle Version2.2.8
MoodleMoodle Version2.2.9
MoodleMoodle Version2.2.10
MoodleMoodle Version2.2.11
MoodleMoodle Version2.3.0
MoodleMoodle Version2.3.1
MoodleMoodle Version2.3.2
MoodleMoodle Version2.3.3
MoodleMoodle Version2.3.4
MoodleMoodle Version2.3.5
MoodleMoodle Version2.3.6
MoodleMoodle Version2.3.7
MoodleMoodle Version2.3.8
MoodleMoodle Version2.3.9
MoodleMoodle Version2.3.10
MoodleMoodle Version2.4.0
MoodleMoodle Version2.4.1
MoodleMoodle Version2.4.2
MoodleMoodle Version2.4.3
MoodleMoodle Version2.4.4
MoodleMoodle Version2.4.5
MoodleMoodle Version2.4.6
MoodleMoodle Version2.4.7
MoodleMoodle Version2.4.8
MoodleMoodle Version2.5.0
MoodleMoodle Version2.5.1
MoodleMoodle Version2.5.2
MoodleMoodle Version2.5.3
MoodleMoodle Version2.5.4
MoodleMoodle Version2.6.0
MoodleMoodle Version2.6.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.2% 0.392
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N