CVE-2011-4590: Medium severity moodle vulnerability
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4590?
CVE-2011-4590 has a medium severity level due to its potential to allow unauthorized access to restricted resources.
How do I fix CVE-2011-4590?
To fix CVE-2011-4590, upgrade Moodle to version 2.0.6 or later, or 2.1.3 or later.
Which versions of Moodle are affected by CVE-2011-4590?
CVE-2011-4590 affects Moodle versions 2.0.0 through 2.0.5 and 2.1.0 through 2.1.2.
What kind of attack does CVE-2011-4590 allow?
CVE-2011-4590 allows remote authenticated users to bypass access restrictions during login attempts.
Is there a workaround for CVE-2011-4590 if I can't update immediately?
There is no official workaround for CVE-2011-4590 other than updating to a patched version of Moodle.