CVE-2011-4285: Medium severity moodle vulnerability
The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
Other sources
The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4285?
CVE-2011-4285 has a medium severity level due to its potential for unauthorized deletion of courses.
How do I fix CVE-2011-4285?
To fix CVE-2011-4285, upgrade to Moodle version 2.0.2 or later.
Who is affected by CVE-2011-4285?
Users running Moodle versions 2.0.0 to 2.0.1 are affected by CVE-2011-4285.
What type of vulnerability is CVE-2011-4285?
CVE-2011-4285 is a privilege escalation vulnerability that allows authenticated users to delete courses.
Can CVE-2011-4285 be exploited remotely?
Yes, CVE-2011-4285 can be exploited remotely by authenticated users with the teacher role.