VulnerabilityModified
CVE-2012-0797
The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.
MEDIUM 5.5EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28126Vendor Advisory
- http://moodle.org/mod/forum/discuss.php?d=194016Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=783532Issue Tracking
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28126Vendor Advisory
- http://moodle.org/mod/forum/discuss.php?d=194016Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=783532Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.