CVE-2014-9060 Information
Feb 14, 2021
cve
Description
The LTI module in Moodle through 2.4.11 2.5.x before 2.5.9 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL which allows remote attackers to trigger the generation of arbitrary messages via a modified URL related to mod/lti/locallib.php and mod/lti/return.php.
Reference
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-47927 http://openwall.com/lists/oss-security/2014/11/17/11 http://www.securitytracker.com/id/1031215 https://moodle.org/mod/forum/discuss.php?d=275165
Share on: