CVE-2011-4287: Medium severity moodle vulnerability
admin/uploaduserform.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4287?
CVE-2011-4287 is considered a medium severity vulnerability due to the potential for unauthorized access to user accounts.
How do I fix CVE-2011-4287?
To fix CVE-2011-4287, upgrade your Moodle installation to version 2.0.3 or later, where the vulnerability is addressed.
What versions of Moodle are affected by CVE-2011-4287?
CVE-2011-4287 affects Moodle versions 2.0.0, 2.0.1, and 2.0.2.
What is the main issue described in CVE-2011-4287?
The main issue in CVE-2011-4287 is that autosubscribed users are not required to change their initial passwords, making it easier for attackers to gain access.
Who is at risk from CVE-2011-4287?
Users of Moodle versions 2.0.0 through 2.0.2 who have autoubscribed accounts are at risk from CVE-2011-4287.