Permissions, Privileges, and Access Controls in Moodle - CVE-2012-0798

 

Permissions, Privileges, and Access Controls in Moodle - CVE-2012-0798

Published: July 17, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43853
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-0798
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2012-0798

Install update from vendor's website.

moodle - update to 2.1.4-1.el6

External References

Related Security Bulletins