CVE-2011-4589: Medium severity moodle vulnerability
backup/moodle2/restorestepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4589?
The severity of CVE-2011-4589 is considered moderate as it allows authenticated users to overwrite course ID numbers.
How do I fix CVE-2011-4589?
To fix CVE-2011-4589, upgrade Moodle to version 2.0.6 or later for the 2.0.x branch and 2.1.3 or later for the 2.1.x branch.
Who is affected by CVE-2011-4589?
Users of Moodle versions 2.0.0 to 2.0.5 and 2.1.0 to 2.1.2 are affected by CVE-2011-4589.
What causes the vulnerability in CVE-2011-4589?
CVE-2011-4589 is caused by a lack of privilege checks when handling course ID numbers during restore actions.
Can CVE-2011-4589 be exploited remotely?
Yes, CVE-2011-4589 can be exploited remotely by authenticated users to change course ID numbers.