CVE-2014-3552: Moodle
Medium severity, CVSS 6.0. EPSS: 1.2% chance of exploitation in the next 30 days.
The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not check whether a session ID is empty, which allows remote authenticated users to hijack sessions via crafted plugin interaction.
Affected products
- Moodle Moodle: version 2.4.0 only; version 2.4.1 only; version 2.4.2 only; version 2.4.3 only; version 2.4.4 only; version 2.4.5 only; …
Published 2014-07-29. Last modified 2026-06-17.