CVE Vulnerabilities

CVE-2012-5472

Published: Nov 21, 2012 | Modified: Jun 21, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 2.2.1 (including) 2.2.1 (including)
Moodle Moodle 2.2.2 (including) 2.2.2 (including)
Moodle Moodle 2.2.3 (including) 2.2.3 (including)
Moodle Moodle 2.2.4 (including) 2.2.4 (including)
Moodle Moodle 2.2.5 (including) 2.2.5 (including)
Moodle Moodle 2.3.1 (including) 2.3.1 (including)
Moodle Moodle 2.3.2 (including) 2.3.2 (including)
Moodle Ubuntu hardy *
Moodle Ubuntu quantal *
Moodle Ubuntu upstream *

References