First published: Thu Apr 29 2010(Updated: )
Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when restoring a course, which allows teachers to create new accounts even if they do not have the moodle/user:create capability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=1.9.0<1.9.8 | 1.9.8 |
composer/moodle/moodle | >=1.8.0<1.8.12 | 1.8.12 |
Moodle | =1.9.4 | |
Moodle | =1.9.1 | |
Moodle | =1.8.8 | |
Moodle | =1.9.6 | |
Moodle | =1.8.2 | |
Moodle | =1.9.2 | |
Moodle | =1.8.6 | |
Moodle | =1.8.5 | |
Moodle | =1.8.3 | |
Moodle | =1.8.9 | |
Moodle | =1.8.7 | |
Moodle | =1.8.10 | |
Moodle | =1.9.3 | |
Moodle | =1.9.5 | |
Moodle | =1.8.11 | |
Moodle | =1.8.4 | |
Moodle | =1.8.1 | |
Moodle | =1.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1616 is considered a medium severity vulnerability due to its potential to allow unauthorized role creation.
To fix CVE-2010-1616, upgrade to Moodle version 1.9.8 or 1.8.12.
CVE-2010-1616 affects Moodle versions 1.8.x and 1.9.x prior to 1.9.8.
The impact of CVE-2010-1616 is that it allows teachers to create new user accounts without the necessary permissions.
Organizations using affected versions of Moodle may face security risks if teachers can create unauthorized accounts.