6
CVSSv2

CVE-2014-3552

Published: 29/07/2014 Updated: 01/12/2020
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle up to and including 2.3.11, 2.4.x prior to 2.4.11, and 2.5.x prior to 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.4.0

moodle moodle 2.4.1

moodle moodle 2.4.2

moodle moodle 2.4.3

moodle moodle 2.4.4

moodle moodle 2.4.9

moodle moodle 2.4.10

moodle moodle 2.4.6

moodle moodle 2.4.8

moodle moodle 2.4.5

moodle moodle 2.4.7

moodle moodle 2.3.4

moodle moodle 2.3.5

moodle moodle 2.3.6

moodle moodle 2.3.7

moodle moodle 2.3.0

moodle moodle 2.3.1

moodle moodle 2.3.10

moodle moodle 2.3.2

moodle moodle 2.3.9

moodle moodle

moodle moodle 2.3.3

moodle moodle 2.3.8

moodle moodle 2.5.1

moodle moodle 2.5.2

moodle moodle 2.5.3

moodle moodle 2.5.4

moodle moodle 2.5.6

moodle moodle 2.5.0

moodle moodle 2.5.5