CVE-2011-4203: Code Injection
CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving the url variable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4203?
CVE-2011-4203 has a medium severity level, allowing attackers to exploit CRLF injection vulnerabilities.
How do I fix CVE-2011-4203?
To fix CVE-2011-4203, upgrade Moodle to version 1.9.15, 2.0.6, 2.1.3, or later.
Which versions of Moodle are affected by CVE-2011-4203?
Moodle versions 1.9.x prior to 1.9.15, 2.0.x prior to 2.0.6, 2.1.x prior to 2.1.3, and 2.2 are affected by CVE-2011-4203.
What type of attack does CVE-2011-4203 enable?
CVE-2011-4203 enables remote attackers to conduct HTTP response splitting attacks via malicious input.
Is CVE-2011-4203 exploitable over the internet?
Yes, CVE-2011-4203 can be exploited by remote attackers over the internet.