PT-2012-1853 · Moodle · Moodle

Xavier Paz

·

Published

2012-07-11

·

Updated

2023-02-13

·

CVE-2011-4305

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Moodle versions 1.9.x through 1.9.13
Description The issue allows remote authenticated users to cause a denial of service, resulting in an infinite request loop. This is achieved by specifying a zero wait time for message refreshing in the message/refresh.php file.
Recommendations For Moodle versions 1.9.x through 1.9.13, update to version 1.9.14 or later to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2011-4305
DSA-2338-1

Affected Products

Moodle