VulnerabilityModified
CVE-2012-4401
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
MEDIUM 4.0EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28207Patch
- http://moodle.org/mod/forum/discuss.php?d=211556
- http://openwall.com/lists/oss-security/2012/09/17/1
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28207Patch
- http://moodle.org/mod/forum/discuss.php?d=211556
- http://openwall.com/lists/oss-security/2012/09/17/1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.