Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4588
Published: July 20, 2012 / Updated: August 11, 2020
Vulnerability identifier: #VU43825
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4588
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.
Affected software
Moodle
Fedora
moodle
Fedora
moodle
How to mitigate CVE-2011-4588
Install update from vendor's website.
moodle - update to 2.1.3-1.el6