← Back

CVE-2014-2572

nvd nist
Published: Mar 24, 2014Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

Affected (2)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
Version 2.6.0
Version 2.6.1

Related CWEs

References (6)

Timeline

No history available yet.