CVE-2012-0792: Infoleak

Published Jan 20, 2012
·
Updated

A number of flaws have been fixed in new upstream Moodle 2.2.1 [1], 2.1.4 [2], 2.0.7 [3], and 1.9.16 [4] releases. These do not have CVEs assigned (request pending), and since Fedora/EPEL will rebase to the latest versions of each branch, I'm summarizing them all here rather than creating a number of separate bugs.

[1] http://docs.moodle.org/dev/Moodle2.2.1releasenotes [2] http://docs.moodle.org/dev/Moodle2.1.4releasenotes [3] http://docs.moodle.org/dev/Moodle2.0.7releasenotes [4] http://docs.moodle.org/dev/Moodle1.9.16releasenotes

MSA-12-0001: Recaptcha transmission consistency issue Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=b608b227bac4efba76da43dabe9bc2e32fb8fa32 Reference: http://moodle.org/mod/forum/discuss.php?d=194008

MSA-12-0002: Personal information leak Affects: 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=36b0ddeed45d0751508dcd9fa50f17fda43bae54 Reference: http://moodle.org/mod/forum/discuss.php?d=194009

MSA-12-0003: Added password protection Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=aa30d3e8ce0dd41d3d0f7dae856beb180fed1f83 Reference: http://moodle.org/mod/forum/discuss.php?d=194011

MSA-12-0004: Added profile image security Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=90911c4ff98dc2078a3acef5ddf5a1a8f7e20ba5 Reference: http://moodle.org/mod/forum/discuss.php?d=194012

MSA-12-0005: Encryption enhancement Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=98456628a24bba25d336860d38a45b5a4e3895da Reference: http://moodle.org/mod/forum/discuss.php?d=194013

MSA-12-0006: Additional email address validation Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-13572 Reference: http://moodle.org/mod/forum/discuss.php?d=194014

MSA-12-0007: Email injection prevention Affects: 2.2, 2.1.x, 2.0.x, 1.9.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=62988bf0bbc73df655f51884aaf1f523928abff9 Reference: http://moodle.org/mod/forum/discuss.php?d=194015

MSA-12-0008: Unsynchronised access via tokens Affects: 2.2, 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-28126 Reference: http://moodle.org/mod/forum/discuss.php?d=194016

MSA-12-0009: Role access issue Affects: 2.2, 2.1.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-29469 Reference: http://moodle.org/mod/forum/discuss.php?d=194017

MSA-12-0010: Unauthorised access to session key Affects: 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-27334 Reference: http://moodle.org/mod/forum/discuss.php?d=194018

MSA-12-0011: Browser autofill password issue Affects: 2.2, 2.1.x, 2.0.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commitdiff;h=6e9989dbd3f261b2e1586ff77b0bf22fc7091485 Reference: http://moodle.org/mod/forum/discuss.php?d=194019

MSA-12-0012: Form validation issue Affects: 2.2, 2.1.x Fix: http://git.moodle.org/gw?p=moodle.git;a=commit;h=51070abc78b9e1db1db9a44855e8623b22bebd48 Reference: http://moodle.org/mod/forum/discuss.php?d=194020

Other sources

mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.

MITRE

Affected Software

15 affected components
Moodle moodle=1.9.1
Moodle moodle=1.9.2
Moodle moodle=1.9.3
Moodle moodle=1.9.4
Moodle moodle=1.9.5
Moodle moodle=1.9.6
Moodle moodle=1.9.7
Moodle moodle=1.9.8
Moodle moodle=1.9.9
Moodle moodle=1.9.10
Moodle moodle=1.9.11
Moodle moodle=1.9.12
Moodle moodle=1.9.13
Moodle moodle=1.9.14
Moodle moodle=1.9.15

Event History

Jan 20, 2012
Data Sourced
via Red Hat·06:30 PM
DescriptionSeverityAffected Software
Jul 17, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2012-0792?

CVE-2012-0792 is classified as a medium severity vulnerability due to the potential unauthorized access to user details.

2

How do I fix CVE-2012-0792?

To fix CVE-2012-0792, upgrade your Moodle installation to version 1.9.16 or later.

3

Which versions of Moodle are affected by CVE-2012-0792?

CVE-2012-0792 affects all Moodle versions from 1.9.1 to 1.9.15.

4

What type of vulnerability is CVE-2012-0792?

CVE-2012-0792 is a security vulnerability that allows authenticated users to obtain information about arbitrary user accounts.

5

Can CVE-2012-0792 lead to data exposure?

Yes, CVE-2012-0792 can lead to the exposure of user names and details through unauthorized queries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203