Improper validation of integrity check value in Moodle - CVE-2012-1170

 

Improper validation of integrity check value in Moodle - CVE-2012-1170

Published: November 14, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30614
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-1170
CWE-ID: CWE-354
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2012-1170

Install update from vendor's website.

Moodle - update to 2.2.2
moodle - addressed in versions 2.1.5-1.el6, 2.1.5-2.el6, 2.1.5-3.el6

External References

Related Security Bulletins