First published: Wed Jul 11 2012(Updated: )
lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =2.0.0 | |
Moodle | =2.0.1 | |
Moodle | =2.0.2 | |
Moodle | =2.0.3 | |
Moodle | =2.0.4 | |
Moodle | =2.1.0 | |
Moodle | =2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4303 is considered a high severity vulnerability due to the risk of unauthorized access to Moodle hubs.
To fix CVE-2011-4303, upgrade your Moodle installation to version 2.0.5 or 2.1.2 or later.
CVE-2011-4303 affects Moodle versions 2.0.0 to 2.0.4 and 2.1.0 to 2.1.1.
CVE-2011-4303 is a security vulnerability that allows remote attackers to bypass access restrictions.
You can check for vulnerability by verifying if your Moodle version is within the affected range of 2.0.x before 2.0.5 or 2.1.x before 2.1.2.