CVE-2012-2354: Medium severity moodle vulnerability
Published Jul 21, 2012
·Updated
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.
Affected Software
9 affected components
Moodle moodle=2.1.0
Moodle moodle=2.1.1
Moodle moodle=2.1.2
Moodle moodle=2.1.3
Moodle moodle=2.1.4
Moodle moodle=2.1.5
Moodle moodle=2.2.0
Moodle moodle=2.2.1
Moodle moodle=2.2.2
Event History
Jul 21, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2354?
CVE-2012-2354 has a medium severity level, impacting user message privacy in Moodle.
2
How do I fix CVE-2012-2354?
To address CVE-2012-2354, you should upgrade to Moodle versions 2.1.6 or 2.2.3 or later.
3
What products are affected by CVE-2012-2354?
CVE-2012-2354 affects Moodle versions 2.1.0 to 2.1.5 and 2.2.0 to 2.2.2.
4
Can unprivileged users exploit CVE-2012-2354?
Yes, CVE-2012-2354 allows remote authenticated users to bypass message reading restrictions.
5
What functionality in Moodle is affected by CVE-2012-2354?
CVE-2012-2354 affects the "Recent conversations" feature, allowing unauthorized access to messages.