CVE-2011-4283: Infoleak
Published Jul 16, 2012
·Updated
Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml.
Affected Software
14 affected componentsFixes available
Moodle moodle=1.9.4
Moodle moodle=1.9.1
Moodle moodle=1.9.6
Moodle moodle=1.9.9
Moodle moodle=2.0.1
Moodle moodle=1.9.2
Moodle moodle=1.9.10
Moodle moodle=1.9.3
Moodle moodle=1.9.5
Moodle moodle=1.9.8
Moodle moodle=1.9.7
Moodle moodle=2.0.0
composer/moodle/moodle>=2.0.0<2.0.2
2.0.2
composer/moodle/moodle>=1.9.0<1.9.11
1.9.11
Remediation
Event History
Jul 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:28 AM
DescriptionSeverityWeaknessAffected Software
May 13, 2022
Advisory Published
via GitHub·01:13 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-4283?
CVE-2011-4283 has a medium severity rating due to its potential to expose sensitive data.
2
How do I fix CVE-2011-4283?
To fix CVE-2011-4283, you should upgrade your Moodle installation to version 1.9.11 or 2.0.2 or later.
3
What versions of Moodle are affected by CVE-2011-4283?
CVE-2011-4283 affects Moodle versions 1.9.x before 1.9.11 and 2.0.x before 2.0.2.
4
What type of information can be exposed by CVE-2011-4283?
CVE-2011-4283 allows remote attackers to obtain sensitive information by accessing the imsenterprise-enrol.xml file.
5
Is there a workaround for CVE-2011-4283?
There are no known workarounds for CVE-2011-4283 other than applying the recommended updates.