CVE-2011-4300: XSS

Published Oct 19, 2011
·
Updated

A number of flaws have been fixed in new upstream Moodle 2.1.2, 2.0.5, and 1.9.14. These do not have CVEs assigned (request pending), and since Fedora/EPEL will rebase to the latest versions of each branch, I'm summarizing them all here rather than creating 16 separate bugs:

MSA-11-0041: Global search authentication issue Affects: 2.1.x 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=5eb1cec34f013fdcb559b66bc401f2845ce0bbb7 Reference: http://moodle.org/mod/forum/discuss.php?d=188323

MSA-11-0040: Potential personal information leak Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&s=MDL-28615 Reference: http://moodle.org/mod/forum/discuss.php?d=188322

MSA-11-0039: Wiki section vulnerability Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=41017112cff7f5bd7969c72d321320f3090e7c68 Reference: http://moodle.org/mod/forum/discuss.php?d=188321

MSA-11-0038: Database injection protection strengthened Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=4a2acd8c7e6c869d5fd5aa686e6e0a3f20c97f15 Reference: http://moodle.org/mod/forum/discuss.php?d=188320

MSA-11-0037: Course section editing injection vulnerability Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=4a2acd8c7e6c869d5fd5aa686e6e0a3f20c97f15 Reference: http://moodle.org/mod/forum/discuss.php?d=188319

MSA-11-0036: Messaging refresh vulnerability Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=97f258fabb3ebfa7acc7c02cb59de92b01710f99 Reference: http://moodle.org/mod/forum/discuss.php?d=188318

MSA-11-0035: Cookie-less session vulnerability Affects: 2.1.x, 2.0.x, (1.9.x if misconfigured) Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=e1e082a809b9a2d3a408cb4d6faa34fdfcf3165c Reference: http://moodle.org/mod/forum/discuss.php?d=188317

MSA-11-0034: Chat module information leak Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=d0157d827bc254ba386a5e5b41b13be2698ee76e Reference: http://moodle.org/mod/forum/discuss.php?d=188316

MSA-11-0033: Site-hub registration identity issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=ca896fdfcfcc87846fa91a297d0aa6999a68c48a Reference: http://moodle.org/mod/forum/discuss.php?d=188315

MSA-11-0032: MNET SSL validation issue Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=54941685e3e86ec085641dcb7ebb1f96f06735b2 Reference: http://moodle.org/mod/forum/discuss.php?d=188314

MSA-11-0031: Forms API constant issue Affects: 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=f1f70bd4dde6cd1ea4bdb8ab28fa3d36a53b89d8 Reference: http://moodle.org/mod/forum/discuss.php?d=188313

MSA-11-0030: Box.net repository integration authentication issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=3deff6c9d2bb4ab3144b3ca7b93d6a2ef6a87af2 Reference: http://moodle.org/mod/forum/discuss.php?d=188312

MSA-11-0029: File visibility issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=f6b07c4da54a9db24723beb147e8a19a3d487e00 Reference: http://moodle.org/mod/forum/discuss.php?d=188311

MSA-11-0028: Wiki comments XSS issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=a459fd90625ae44d7b3ac10b65da2dc631a418e7 Reference: http://moodle.org/mod/forum/discuss.php?d=188310

MSA-11-0027: Wiki pages reference forgery issue Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=48346fb11f8ced06a05c0618b02a3a925b34ec59 Reference: http://moodle.org/mod/forum/discuss.php?d=188309

MSA-11-0026: Fields in user upload CSV not being escaped Affects: 1.9.x Reference: http://moodle.org/mod/forum/discuss.php?d=182743

Other sources

The filebrowser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

GitHub

The filebrowser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

MITRE

Affected Software

9 affected componentsFixes available
composer/moodle/moodle>=2.0.0<2.0.5
2.0.5
composer/moodle/moodle>=2.1<2.1.2
2.1.2
Moodle moodle=2.0.0
Moodle moodle=2.0.1
Moodle moodle=2.0.2
Moodle moodle=2.0.3
Moodle moodle=2.0.4
Moodle moodle=2.1.0
Moodle moodle=2.1.1

Event History

Oct 19, 2011
Data Sourced
via Red Hat·08:13 PM
DescriptionSeverityAffected Software
Jul 11, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:13 AM

Frequently Asked Questions

1

What is the severity of CVE-2011-4300?

The severity of CVE-2011-4300 is not explicitly detailed in the public resources, but it affects multiple versions of Moodle that could potentially lead to security risks.

2

How do I fix CVE-2011-4300?

To fix CVE-2011-4300, update your Moodle installation to version 2.1.2, 2.0.5, or 1.9.14 or later.

3

Which Moodle versions are affected by CVE-2011-4300?

CVE-2011-4300 affects Moodle versions 2.0.0 up to 2.0.4, and specific versions of 2.1.0, 2.1.1, and others.

4

Is CVE-2011-4300 still a concern for recently updated Moodle installations?

If your Moodle installation has been updated to version 2.1.2 or later, CVE-2011-4300 is no longer a concern.

5

What should I do if I cannot update my Moodle version due to compatibility issues related to CVE-2011-4300?

If you cannot update due to compatibility issues, consider evaluating the impacted features and applying security best practices to mitigate risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203