CVE-2012-1159: Infoleak
Moodle before 2.2.2 is vulnerable to information disclosure because course backups were including users' private files.
Other sources
Moodle before 2.2.2: Overview report allows users to see hidden courses
— Debian
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1159?
CVE-2012-1159 has been classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2012-1159?
To fix CVE-2012-1159, upgrade Moodle to at least version 2.2.2 or apply any relevant patches.
What versions of Moodle are affected by CVE-2012-1159?
CVE-2012-1159 affects Moodle versions prior to 2.2.2, including 1.9.17 and versions between 2.0 and 2.2.1.
What type of vulnerability is CVE-2012-1159?
CVE-2012-1159 is an information disclosure vulnerability that allows exposure of users' private files during course backups.
Which systems are vulnerable to CVE-2012-1159?
Systems running vulnerable versions of Moodle, including versions prior to 2.2.2, are at risk from CVE-2012-1159.