CVE-2011-4295: Medium severity moodle vulnerability
The moodleenrolexternal:roleassign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4295?
CVE-2011-4295 is considered a high severity vulnerability as it allows remote authenticated users to gain unauthorized privileges in Moodle.
How do I fix CVE-2011-4295?
To fix CVE-2011-4295, upgrade Moodle to version 2.0.4 or 2.1.1 or later, which includes the necessary authorization checks.
Which versions of Moodle are affected by CVE-2011-4295?
CVE-2011-4295 affects Moodle versions 2.0.0 to 2.0.3 and 2.1.0.
Can CVE-2011-4295 be exploited remotely?
Yes, CVE-2011-4295 can be exploited remotely by authenticated users without proper authorization checks.
What is the impact of CVE-2011-4295 on Moodle users?
The impact of CVE-2011-4295 allows authenticated users to make unauthorized role assignments, potentially escalating their privileges.