Permissions, Privileges, and Access Controls in Moodle - CVE-2012-3388

 

Permissions, Privileges, and Access Controls in Moodle - CVE-2012-3388

Published: July 24, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43788
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-3388
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to manipulate data.

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2012-3388

Install update from vendor's website.

moodle - addressed in versions 1.9.19-1.el5, 1.9.19-2.el5, 1.9.19-3.el5, 2.1.7-1.el6

External References

Related Security Bulletins