Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4583

 

Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4583

Published: July 20, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43833
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4583
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2011-4583

Install update from vendor's website.

moodle - update to 2.1.3-1.el6

External References

Related Security Bulletins