CVE-2012-2359: Medium severity moodle vulnerability
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2359?
CVE-2012-2359 is classified as a moderate severity vulnerability due to privilege escalation risks.
How do I fix CVE-2012-2359?
To fix CVE-2012-2359, upgrade your Moodle installation to version 2.0.9, 2.1.6, or 2.2.3 or later.
What versions of Moodle are affected by CVE-2012-2359?
CVE-2012-2359 affects Moodle versions prior to 2.0.9, 2.1.6, and 2.2.3.
Who can exploit the vulnerability identified in CVE-2012-2359?
CVE-2012-2359 can be exploited by remote authenticated users with teacher roles.
What capabilities can be gained by exploiting CVE-2012-2359?
Exploiting CVE-2012-2359 allows users to modify their own capabilities, which may include obtaining the backup:userinfo capability.