CVE Vulnerabilities

CVE-2011-4584

Published: Jul 20, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle1.9.1 (including)1.9.1 (including)
MoodleMoodle1.9.2 (including)1.9.2 (including)
MoodleMoodle1.9.3 (including)1.9.3 (including)
MoodleMoodle1.9.4 (including)1.9.4 (including)
MoodleMoodle1.9.5 (including)1.9.5 (including)
MoodleMoodle1.9.6 (including)1.9.6 (including)
MoodleMoodle1.9.7 (including)1.9.7 (including)
MoodleMoodle1.9.8 (including)1.9.8 (including)
MoodleMoodle1.9.9 (including)1.9.9 (including)
MoodleMoodle1.9.10 (including)1.9.10 (including)
MoodleMoodle1.9.11 (including)1.9.11 (including)
MoodleMoodle1.9.12 (including)1.9.12 (including)
MoodleMoodle1.9.13 (including)1.9.13 (including)
MoodleMoodle1.9.14 (including)1.9.14 (including)
MoodleMoodle2.0.0 (including)2.0.0 (including)
MoodleMoodle2.0.1 (including)2.0.1 (including)
MoodleMoodle2.0.2 (including)2.0.2 (including)
MoodleMoodle2.0.3 (including)2.0.3 (including)
MoodleMoodle2.0.4 (including)2.0.4 (including)
MoodleMoodle2.0.5 (including)2.0.5 (including)
MoodleMoodle2.1.0 (including)2.1.0 (including)
MoodleMoodle2.1.1 (including)2.1.1 (including)
MoodleMoodle2.1.2 (including)2.1.2 (including)
MoodleUbuntuhardy*
MoodleUbuntulucid*
MoodleUbuntumaverick*
MoodleUbuntunatty*
MoodleUbuntuoneiric*

References