CVE-2012-1160: Medium severity moodle vulnerability
Published Nov 14, 2019
·Updated
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
Affected Software
5 affected components
debian/moodle
Moodle moodle<2.2.2
Fedoraproject Fedora=15
Fedoraproject Fedora=16
Fedoraproject Fedora=17
Remediation
Patch Available
Patch Available
Event History
Nov 14, 2019
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2012-1160?
CVE-2012-1160 is classified as a moderate severity vulnerability due to the potential for unauthorized access to forum functionalities.
2
How do I fix CVE-2012-1160?
To fix CVE-2012-1160, upgrade to Moodle version 2.2.2 or later to address the permission issue.
3
What are the affected versions for CVE-2012-1160?
CVE-2012-1160 affects Moodle versions prior to 2.2.2, including various distributions like Debian and specific Fedora releases.
4
Who can exploit CVE-2012-1160?
Unenrolled users can exploit CVE-2012-1160 to subscribe or unsubscribe from forum topics in Moodle.
5
What is the nature of the vulnerability in CVE-2012-1160?
The vulnerability in CVE-2012-1160 is a permission issue that allows users without proper enrollment to manipulate forum subscriptions.