#VU43829 Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4592
Published: July 20, 2012 / Updated: August 11, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.