Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4592

 

Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4592

Published: July 20, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43829
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2011-4592
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: moodle.org
Affected software:
Moodle

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.


How to mitigate CVE-2011-4592

Install update from vendor's website.

Sources