CVE-2011-4297: Medium severity moodle vulnerability
Published Jul 16, 2012
·Updated
comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.
Affected Software
7 affected componentsFixes available
Moodle moodle=2.0.2
Moodle moodle=2.0.1
Moodle moodle=2.0.3
Moodle moodle=2.0.0
Moodle moodle=2.1.0
composer/moodle/moodle>=2.1.0<2.1.1
2.1.1
composer/moodle/moodle>=2.0.0<2.0.4
2.0.4
Remediation
Event History
Jul 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:13 AM
Data Sourced
via GitHub·01:13 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4297?
CVE-2011-4297 is classified as a vulnerability that can lead to unauthorized comment posting due to insufficient restrictions.
2
How do I fix CVE-2011-4297?
To fix CVE-2011-4297, upgrade Moodle to version 2.0.4 or 2.1.1 or later.
3
What versions of Moodle are affected by CVE-2011-4297?
CVE-2011-4297 affects Moodle versions 2.0.0 through 2.0.3 and 2.1.0.
4
Can remote attackers exploit CVE-2011-4297?
Yes, remote attackers can exploit CVE-2011-4297 to post comments by using the guest role.
5
What component of Moodle is vulnerable in CVE-2011-4297?
CVE-2011-4297 affects the comment/lib.php component in Moodle.