Code Injection in Moodle - CVE-2012-0796

 

Code Injection in Moodle - CVE-2012-0796

Published: July 17, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43851
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0796
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to manipulate data.

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2012-0796

Install update from vendor's website.

moodle - update to 2.1.4-1.el6

External References

Related Security Bulletins