PT-2012-1827 · Moodle · Moodle
Amr Hourani
·
Published
2012-07-16
·
Updated
2022-05-13
·
CVE-2011-4279
CVSS v4.0
6.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Moodle versions 2.0.x through 2.0.1
Description
The issue makes it easier for remote attackers to obtain potentially sensitive information via vectors involving the use of a search engine. This is because the forceloginforprofiles setting is not used for course-profiles access control.
Recommendations
For Moodle versions 2.0.x through 2.0.1, update to version 2.0.2 or later to resolve the issue.
Fix
Information Disclosure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moodle