CVE-2012-0800: Infoleak
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0800?
CVE-2012-0800 is considered a medium severity vulnerability due to its potential to expose user passwords.
How do I fix CVE-2012-0800?
To fix CVE-2012-0800, upgrade Moodle to version 2.0.7, 2.1.4, or 2.2.1 or later.
What versions of Moodle are affected by CVE-2012-0800?
CVE-2012-0800 affects Moodle versions 2.0.x prior to 2.0.7, 2.1.x prior to 2.1.4, and 2.2.x prior to 2.2.1.
What type of attack is facilitated by CVE-2012-0800?
CVE-2012-0800 facilitates physical proximity attacks that allow unauthorized access to user passwords.
Can CVE-2012-0800 impact all Moodle installations?
No, CVE-2012-0800 specifically affects older versions of Moodle and does not impact the latest ones after the mentioned updates.