First published: Mon Jul 16 2012(Updated: )
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =2.0.0 | |
Moodle | =2.0.1 | |
Moodle | =2.0.2 | |
Moodle | =2.0.3 | |
Moodle | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4296 is considered a medium severity vulnerability due to its potential to allow unauthorized modification of course filters.
To fix CVE-2011-4296, upgrade Moodle to version 2.0.4 or later for 2.0.x or 2.1.1 or later for 2.1.x.
CVE-2011-4296 affects users of Moodle versions 2.0.0 to 2.0.3 and 2.1.0.
CVE-2011-4296 can facilitate attacks that allow remote authenticated users to alter course filters by exploiting improper role capabilities.
CVE-2011-4296 is a remote vulnerability as it can be exploited by authenticated users from outside the system.