CVE-2011-4296: Medium severity moodle vulnerability
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4296?
CVE-2011-4296 is considered a medium severity vulnerability due to its potential to allow unauthorized modification of course filters.
How do I fix CVE-2011-4296?
To fix CVE-2011-4296, upgrade Moodle to version 2.0.4 or later for 2.0.x or 2.1.1 or later for 2.1.x.
Who is affected by CVE-2011-4296?
CVE-2011-4296 affects users of Moodle versions 2.0.0 to 2.0.3 and 2.1.0.
What type of attack can CVE-2011-4296 facilitate?
CVE-2011-4296 can facilitate attacks that allow remote authenticated users to alter course filters by exploiting improper role capabilities.
Is CVE-2011-4296 a local or remote vulnerability?
CVE-2011-4296 is a remote vulnerability as it can be exploited by authenticated users from outside the system.