CVE-2012-1168: Input Validation
Published Nov 14, 2019
·Updated
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
Affected Software
6 affected components
debian/moodle
Moodle Moodle<2.2.2
Fedoraproject Fedora=15
Fedoraproject Fedora=16
Fedoraproject Fedora=17
redhat Enterprise Linux=6.0
Remediation
Patch Available
Event History
Nov 14, 2019
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2012-1168?
CVE-2012-1168 is rated as medium severity due to the risk of user passwords being reset unintentionally.
2
How do I fix CVE-2012-1168?
To address CVE-2012-1168, upgrade to Moodle version 2.2.2 or later.
3
What are the affected versions of Moodle in CVE-2012-1168?
CVE-2012-1168 affects Moodle versions prior to 2.2.2.
4
Can CVE-2012-1168 affect user accounts in Moodle?
Yes, CVE-2012-1168 can lead to unintentional password changes, affecting user account access.
5
Which operating systems are impacted by CVE-2012-1168?
CVE-2012-1168 impacts Moodle installations on Fedora 15, 16, 17 and Red Hat Enterprise Linux 6.0.