CVE-2011-4284: Infoleak
Published Jul 16, 2012
·Updated
Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.
Affected Software
3 affected componentsFixes available
Moodle moodle=2.0.1
Moodle moodle=2.0.0
composer/moodle/moodle>=2.0.0<2.0.2
2.0.2
Remediation
Event History
Jul 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:13 AM
Frequently Asked Questions
1
What is the severity of CVE-2011-4284?
CVE-2011-4284 has a moderate severity rating as it allows remote attackers to access sensitive information.
2
How do I fix CVE-2011-4284?
To fix CVE-2011-4284, upgrade your Moodle installation to version 2.0.2 or later.
3
What versions of Moodle are affected by CVE-2011-4284?
CVE-2011-4284 affects Moodle versions 2.0.0 and 2.0.1.
4
What type of attack does CVE-2011-4284 enable?
CVE-2011-4284 enables remote attackers to obtain sensitive information from the myprofile block.
5
Is there a workaround for CVE-2011-4284?
There are no official workarounds for CVE-2011-4284; patching to a secure version is recommended.