Permissions, Privileges, and Access Controls in Moodle - CVE-2012-0798
Published: July 17, 2012 / Updated: August 11, 2020
Vulnerability identifier: #VU43853
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0798
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to read and manipulate data.
The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.
Affected software
Moodle
Fedora
moodle
Fedora
moodle
How to mitigate CVE-2012-0798
Install update from vendor's website.
moodle - update to 2.1.4-1.el6