CVE-2006-4936: Input Validation
Published Sep 23, 2006
·Updated
Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.
Affected Software
3 affected componentsFixes available
composer/moodle/moodle<1.6.2
1.6.2
Moodle moodle<=1.6.1
Moodle moodle=1.6.0
Event History
Sep 23, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 1, 2022
Advisory Published
via GitHub·07:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2006-4936?
The severity of CVE-2006-4936 is currently unspecified, highlighting potential impacts on Moodle's security.
2
How do I fix CVE-2006-4936?
To fix CVE-2006-4936, upgrade Moodle to version 1.6.2 or later.
3
What versions of Moodle are affected by CVE-2006-4936?
CVE-2006-4936 affects Moodle versions prior to 1.6.2, including 1.6.0 and 1.6.1.
4
What potential impact does CVE-2006-4936 have?
CVE-2006-4936 could allow remote attackers to exploit vulnerabilities due to improper validation of the module instance id.
5
Is CVE-2006-4936 a critical vulnerability?
CVE-2006-4936 is not specifically labeled as critical but presents a risk that could be leveraged by attackers.