Permissions, Privileges, and Access Controls in Moodle - CVE-2012-2359

 

Permissions, Privileges, and Access Controls in Moodle - CVE-2012-2359

Published: July 21, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43810
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-2359
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2012-2359

Install update from vendor's website.

moodle - update to 2.1.6-1.el6

External References

Related Security Bulletins