CVE Vulnerabilities

CVE-2012-4408

Published: Sep 19, 2012 | Modified: Dec 01, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 2.1.0 (including) 2.1.0 (including)
Moodle Moodle 2.1.1 (including) 2.1.1 (including)
Moodle Moodle 2.1.2 (including) 2.1.2 (including)
Moodle Moodle 2.1.3 (including) 2.1.3 (including)
Moodle Moodle 2.1.4 (including) 2.1.4 (including)
Moodle Moodle 2.1.5 (including) 2.1.5 (including)
Moodle Moodle 2.1.6 (including) 2.1.6 (including)
Moodle Moodle 2.1.7 (including) 2.1.7 (including)

References