Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.3
CVE-2014-0218: Moodle URL Downloader Allows Malicious Script Injection
CVE-2014-0218 · published 12 years ago
Summary
A security flaw in Moodle's URL Downloader feature allows attackers to inject malicious code into a website, potentially allowing them to steal sensitive information or take control of user sessions. This issue affects Moodle versions 2.3.11 and earlier, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3. To stay secure, update Moodle to the latest patched version.
What to do
- Update moodle moodle to version 2.4.10.
- Update moodle moodle to version 2.5.6.
- Update moodle moodle to version 2.6.3.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| composer | moodle | moodle |
< 2.4.10 >= 2.5.0, < 2.5.6 >= 2.6.0, < 2.6.3 Fix: upgrade to 2.4.10
|
| – | moodle | moodle |
<= 2.3.11 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 2.0.8 2.0.9 2.1.0 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.1.10 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 2.2.9 2.2.10 2.2.11 2.3.0 2.3.1 2.3.2 2.3.3 2.3.4 2.3.5 2.3.6 2.3.7 2.3.8 2.3.9 2.3.10 2.4.0 2.4.1 2.4.2 2.4.3 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 2.5.0 2.5.1 2.5.2 2.5.3 2.5.4 2.5.5 2.6.0 2.6.1 2.6.2 cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |
Original advisory text
Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows ...
Cross-site scripting (XSS) vulnerability in the URL downloader repository in repository/url/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
References
- https://nvd.nist.gov/vuln/detail/CVE-2014-0218
- https://moodle.org/mod/forum/discuss.php?d=260366
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-45332
- http://openwall.com/lists/oss-security/2014/05/19/1
- https://github.com/moodle/moodle/commit/5c276a4c324b5137064496d6dd68e71476015fcd
- https://github.com/moodle/moodle/commit/729783c4ba971413198f30784b48e3f2107a8da6
- https://github.com/moodle/moodle/commit/b8a6f7d19d623bcf992d8ecda94324100bc50e9d
- https://github.com/moodle/moodle/commit/c5e8a036c509197bb2927f47c0579992be479f35
- https://web.archive.org/web/20141224120458/http://www.securityfocus.com/bid/6747...
- https://github.com/advisories/GHSA-ch68-5r37-p7c3
- http://www.securityfocus.com/bid/67479
Severity
4.3
Medium
Exploitation
EPSS 2%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published27 May 2014
Updated14 Aug 2026
First seen6 Mar 2026
Monitor software like this
Free during beta