Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Flaws in Moodle CMS positioned hundreds of e-gaining knowledge of websites at chance

Flaws in Moodle CMS positioned hundreds of e-gaining knowledge of websites at chance

Latest Govt. Jobs 23:17:00 News Edit
Serious flaws are patched in the Moodle e-learning platform.

Organizations that use the popular Moodle learning management system should deploy the latest patches as soon as possible because they fix vulnerabilities that could allow attackers to take over web servers.
Moodle is an open source platform used by schools, universities, and other organizations to set up websites with interactive online courses. It's used by more than 78,000 e-learning websites from 234 countries that together have more than 100 million users.
A week ago the Moodle developers released updates for the still supported branches of the platform: 3.2.2, 3.1.5, 3.0.9 and 2.7.19. The release notes mentioned that "a number of security related issues were resolved," but didn't provide any additional details about their nature or impact.
The severity of the flaws became apparent Monday, when security researcher Netanel Rubin, who found the vulnerabilities, published a detailed blog post about them. They don't seem too critical on their own, but when combined, they allow attackers to create hidden administrative accounts and execute malicious PHP code on the underlying server.
The exploit takes advantage of some false assumptions made by the developers, which Rubin described as a logic flaw, an Object Injection, a double SQL injection, and an overly permissive administrative dashboard.
The logic issue stems from the reimplementation of a certain function without taking into account decisions made by the original function's developers. According to the researcher, it is the result of "having too much code, too many developers and lacking documentation."
"Keep in mind that logical vulnerabilities can and will occur in almost all systems featuring a large code base," Rubin said. "Security issues in large code bases is, of course, not Moodle specific."
One factor that somewhat limits the impact of the flaws is that exploiting them requires an account on the targeted website. That's not much of a barrier though considering how many registered users these websites have.
Gaining administrative privileges on the Moodle platform is not only dangerous because attackers could install a PHP backdoor by uploading malicious plug-ins or templates, but also because Moodle installations store sensitive and private information about students taking online courses.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Alcatel 1x with Android Oreo (Go ed...

Huawei P20, P20 Pro, P20 Lite price

Xiaomi Redmi 5 with 18:9 display
Flaws in Moodle CMS positioned hundreds of e-gaining knowledge of websites at chance Flaws in Moodle CMS positioned hundreds of e-gaining knowledge of websites at chance Reviewed by Latest Govt. Jobs on 23:17:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • 1More iBFree earphones review
    1More iBFree earphones review
    22.01.2018 - 0 Comments
    The headphone jack has been in a bit of a limbo as a a few smartphone makers have ditched it. However, with…
  • What Is “Differential Privacy,” and How Does It Keep My Data Anonymous?
    What Is “Differential Privacy,” and How Does It Keep My Data Anonymous?
    11.02.2017 - 0 Comments
    Apple is staking their reputation on ensuring the data it collects from you remains private. How? By…
  • Google’s Clips camera
    Google’s Clips camera
    01.03.2018 - 0 Comments
    Google says Clips, which was announced in October, is the outgrowth of years of research into what people…
  • UPI & USSD txns see exponential growth while card txns dip in January: RBI data
    UPI & USSD txns see exponential growth while card txns dip in January: RBI data
    14.02.2017 - 0 Comments
    Data released by the Reserve Bank of India shows that the number of transactions on Unified Payments…
  • Samsung Gear S2 Review: Bold, Stylish & Innovative
    Samsung Gear S2 Review: Bold, Stylish & Innovative
    11.02.2017 - 0 Comments
    Smartwatches might have failed to catch on as planned, but company’s like Apple and Samsung are still…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...

Random Posts

  • Vivo V5 Plus review: Great selfies, good performance
    Vivo V5 Plus review: Great selfies, good performance
    31.01.2017 - 0 Comments
     So what does one expect from a phone they are ready to spend over Rs 25,000 on? We'd say a great…
  • LG’s 2017 K-series will launch in India on February 22
    LG’s 2017 K-series will launch in India on February 22
    19.02.2017 - 0 Comments
    LG will be launching its ‘K Series’ in India on February 22. LG has sent out press invites for an event in…
  • HTC smartphone with Snapdragon 625
    HTC smartphone with Snapdragon 625
    05.02.2018 - 0 Comments
    It shouldn’t take HTC long to publically announce the smartphone. (Image for representation) HTC is…
  • How to Grow a Beard Faster Naturally? (For Men)
    How to Grow a Beard Faster Naturally? (For Men)
    20.04.2016 - 0 Comments
    How to grow a beard faster naturally for men? Men develop beards for some reasons; to have manly look that…
  • AMD reveals Ryzen five charges because it sidesteps performance questions
    AMD reveals Ryzen five charges because it sidesteps performance questions
    24.03.2017 - 0 Comments
    As AMD reveals its Ryzen 5 prices and release date, the company marks an important transition: After…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!