Permissions, Privileges, and Access Controls in Moodle - CVE-2012-5480
Published: November 21, 2012 / Updated: August 11, 2020
Vulnerability identifier: #VU43315
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-5480
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.
Affected software
Moodle
How to mitigate CVE-2012-5480
Install update from vendor's website.