{"id":2102,"date":"2020-05-19T16:47:22","date_gmt":"2020-05-19T21:47:22","guid":{"rendered":"https:\/\/cert.pa\/?p=2102"},"modified":"2020-05-19T16:47:38","modified_gmt":"2020-05-19T21:47:38","slug":"csirt-panama-aviso-2020-05-19-moodle-actualizaciones-de-multiples-vulnerabilidades-que-afectan-al-sistema-de-gestion-de-aprendizaje-moodle","status":"publish","type":"post","link":"https:\/\/cert.pa\/?p=2102","title":{"rendered":"CSIRT Panam\u00e1 Aviso 2020-05-19 Moodle: Actualizaciones de M\u00faltiples vulnerabilidades que afectan al sistema de gesti\u00f3n de aprendizaje Moodle."},"content":{"rendered":"\n<p>Gravedad:Alta&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vulnerabilidad: CVE-2020-10738 \/ CVE-2018-1999024<br>\nFecha de publicaci\u00f3n: Mayo 19, 2020<br>\n\u00daltima revisi\u00f3n: Mayo 19, 2020<br>\nPortal: https:\/\/moodle.org\/<\/p>\n\n\n\n<p><strong>Sistemas Afectados:<\/strong><br>\nVulnerabilidades de seguridad que afectan a todas las versiones de Moodle\nversiones 3.8 hasta la 3.8.2, 3.7 hasta la 3.7.5, 3.6 hasta la 3.6.9, 3.5 hasta\nla 3.5.11 y versiones anteriores.<\/p>\n\n\n\n<p><strong>I. Descripci\u00f3n<\/strong><br>\nActualizaci\u00f3n del sistema de gesti\u00f3n de aprendizaje Moodle referente a\nm\u00faltiples vulnerabilidades que afectan a sus productos.<\/p>\n\n\n\n<p><strong>II. Impacto<\/strong><\/p>\n\n\n\n<p><strong>Vulnerabilidad:<\/strong>&nbsp;CVE-2020-10738<\/p>\n\n\n\n<p>Debido a la insuficiente validaci\u00f3n de datos\ningresados por el usuario al procesar paquetes SCORM, un atacante remoto podr\u00eda\nsubir paquetes especialmente dise\u00f1ados, que una vez agregados al curso, se\npodr\u00e1n comunicar con el servicio web, logrando comprometer completamente al\nsistema afectado mediante la ejecuci\u00f3n de c\u00f3digo remoto.<strong> <\/strong><\/p>\n\n\n\n<p><strong>Vulnerabilidad:<\/strong>&nbsp;CVE-2018-1999024<\/p>\n\n\n\n<p>Debido a la insuficiente sanitizaci\u00f3n de datos\ningresados por el usuario en el macro \u201cunicode{}\u201d en \u201cMathJax\u201d, un atacante\nremoto podr\u00eda enga\u00f1ar a una v\u00edctima para que acceda a un enlace especialmente\ndise\u00f1ado, logrando ejecutar HTML y c\u00f3digo JavaScript en el contexto del sitio\nvulnerable. La explotaci\u00f3n de esta vulnerabilidad XSS (Cross-site scripting)\npermitir\u00eda al atacante el robo de credenciales, cambiar la apariencia del sitio\nweb y hasta conducir al usuario para descargar malware.<\/p>\n\n\n\n<p><strong>III. Referencia a soluciones, herramientas e\ninformaci\u00f3n<\/strong><\/p>\n\n\n\n<p>Actualizar a la versi\u00f3n 3.8.3, 3.7.6, 3.6.10 \u00f3\n3.5.12 de Moodle, mediante su sitio web (https:\/\/download.moodle.org\/)<\/p>\n\n\n\n<p><strong>Fuentes:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Moodle docs. Security announcements. Recopilado en: <a href=\"https:\/\/moodle.org\/mod\/forum\/discuss.php?d=403512\">https:\/\/moodle.org\/mod\/forum\/discuss.php?d=403512<\/a><\/li><li>Common Vulnerabilities and Exposures (CVE). Recopilado en:\u00a0<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-1999024\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-1999024<\/a><\/li><li>Moodle docs. Security announcements. Recopilado en:      <a href=\"https:\/\/moodle.org\/mod\/forum\/discuss.php?d=403513\">https:\/\/moodle.org\/mod\/forum\/discuss.php?d=403513<\/a><\/li><li>Common Vulnerabilities and Exposures (CVE). Recopilado en:\u00a0<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-10738\">https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-10738<\/a><\/li><li>CSIRT Chile. 19 de mayo del 2020. Vulnerabilidades. Recopilado en: <a href=\"https:\/\/www.csirt.gob.cl\/vulnerabilidades\/9vsa20-00216-01\/\">https:\/\/www.csirt.gob.cl\/vulnerabilidades\/9vsa20-00216-01\/<\/a><\/li><\/ul>\n\n\n\n<p><strong>Informaci\u00f3n de contacto<\/strong><br>\nCSIRT PANAMA<br>\nComputer Security Incident Response Team Autoridad Nacional para la Innovacion\nGubernamental<br>\nE-Mail: info@cert.pa<br>\nPhone: +507 520-CERT (2378)<br>\nWeb: https:\/\/cert.pa<br>\nTwitter: @CSIRTPanama<br>\nKey ID: 16F2B124<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gravedad:Alta&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vulnerabilidad: CVE-2020-10738 \/ CVE-2018-1999024 Fecha de publicaci\u00f3n: Mayo 19, 2020 \u00daltima revisi\u00f3n: Mayo 19, 2020 Portal: https:\/\/moodle.org\/ Sistemas Afectados: Vulnerabilidades de seguridad que afectan a todas las versiones de Moodle versiones 3.8 hasta la&#8230;<\/p>\n","protected":false},"author":4,"featured_media":2103,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-2102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-avisos-de-seguridad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2102"}],"version-history":[{"count":1,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2102\/revisions"}],"predecessor-version":[{"id":2104,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/posts\/2102\/revisions\/2104"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=\/wp\/v2\/media\/2103"}],"wp:attachment":[{"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cert.pa\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}