CVE-2011-4303: Medium severity moodle vulnerability
lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registrationhubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4303?
CVE-2011-4303 is considered a high severity vulnerability due to the risk of unauthorized access to Moodle hubs.
How do I fix CVE-2011-4303?
To fix CVE-2011-4303, upgrade your Moodle installation to version 2.0.5 or 2.1.2 or later.
Which versions of Moodle are affected by CVE-2011-4303?
CVE-2011-4303 affects Moodle versions 2.0.0 to 2.0.4 and 2.1.0 to 2.1.1.
What type of vulnerability is CVE-2011-4303?
CVE-2011-4303 is a security vulnerability that allows remote attackers to bypass access restrictions.
Can I check if my Moodle installation is vulnerable to CVE-2011-4303?
You can check for vulnerability by verifying if your Moodle version is within the affected range of 2.0.x before 2.0.5 or 2.1.x before 2.1.2.