VulnerabilityModified
CVE-2012-6102
lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
MEDIUM 6.4EPSS 1.36%
Does this matter?
Lower severity and a low EPSS score (1.36%). Track it; it rarely justifies an emergency change on its own.
Description
lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.36% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37244
- http://openwall.com/lists/oss-security/2013/01/21/1
- https://moodle.org/mod/forum/discuss.php?d=220163Vendor Advisory
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37244
- http://openwall.com/lists/oss-security/2013/01/21/1
- https://moodle.org/mod/forum/discuss.php?d=220163Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.