First published: Sat Sep 23 2006(Updated: )
Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <1.6.2 | 1.6.2 |
Moodle | <=1.6.1 | |
Moodle | =1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-4936 is currently unspecified, highlighting potential impacts on Moodle's security.
To fix CVE-2006-4936, upgrade Moodle to version 1.6.2 or later.
CVE-2006-4936 affects Moodle versions prior to 1.6.2, including 1.6.0 and 1.6.1.
CVE-2006-4936 could allow remote attackers to exploit vulnerabilities due to improper validation of the module instance id.
CVE-2006-4936 is not specifically labeled as critical but presents a risk that could be leveraged by attackers.