First published: Wed Jul 11 2012(Updated: )
message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.9.4 | |
Moodle | =1.9.1 | |
Moodle | =1.9.6 | |
Moodle | =1.9.9 | |
Moodle | =1.9.11 | |
Moodle | =1.9.2 | |
Moodle | =1.9.12 | |
Moodle | =1.9.10 | |
Moodle | =1.9.3 | |
Moodle | =1.9.13 | |
Moodle | =1.9.5 | |
Moodle | =1.9.8 | |
Moodle | =1.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4305 is considered to have a high severity due to its potential to cause a denial of service.
To fix CVE-2011-4305, upgrade to Moodle version 1.9.14 or later.
CVE-2011-4305 affects Moodle versions 1.9.1 to 1.9.13.
CVE-2011-4305 is a denial of service vulnerability.
No, CVE-2011-4305 requires remote authenticated users to exploit the vulnerability.