Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4293
Published: July 16, 2012 / Updated: August 11, 2020
Moodle
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.