CVE-2011-4301: Medium severity moodle vulnerability
The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.
Other sources
The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4301?
CVE-2011-4301 is classified as having a medium severity, allowing attackers to exploit unexpected form submissions.
How do I fix CVE-2011-4301?
To fix CVE-2011-4301, upgrade to Moodle 1.9.14, 2.0.5, or 2.1.2 or later.
What versions of Moodle are affected by CVE-2011-4301?
Moodle versions affected by CVE-2011-4301 include 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2.
What is the nature of the vulnerability in CVE-2011-4301?
The vulnerability in CVE-2011-4301 arises from the `MoodleQuickForm` class not properly handling Forms API `setConstant` operations.
Can CVE-2011-4301 lead to remote exploitation?
Yes, CVE-2011-4301 can potentially allow remote attackers to submit unexpected content through forms.