First published: Thu Nov 14 2019(Updated: )
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/moodle | ||
Moodle | <2.2.2 | |
Fedora | =15 | |
Fedora | =16 | |
Fedora | =17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1160 is classified as a moderate severity vulnerability due to the potential for unauthorized access to forum functionalities.
To fix CVE-2012-1160, upgrade to Moodle version 2.2.2 or later to address the permission issue.
CVE-2012-1160 affects Moodle versions prior to 2.2.2, including various distributions like Debian and specific Fedora releases.
Unenrolled users can exploit CVE-2012-1160 to subscribe or unsubscribe from forum topics in Moodle.
The vulnerability in CVE-2012-1160 is a permission issue that allows users without proper enrollment to manipulate forum subscriptions.