First published: Sat Jul 21 2012(Updated: )
mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =2.1.0 | |
Moodle | =2.1.1 | |
Moodle | =2.1.2 | |
Moodle | =2.1.3 | |
Moodle | =2.1.4 | |
Moodle | =2.1.5 | |
Moodle | =2.2.0 | |
Moodle | =2.2.1 | |
Moodle | =2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2366 is classified as a medium severity vulnerability due to the potential for unauthorized database modifications.
To fix CVE-2012-2366, you should upgrade to Moodle versions 2.1.6 or 2.2.3 or later.
CVE-2012-2366 affects users of Moodle versions 2.1.x before 2.1.6 and 2.2.x before 2.2.3.
CVE-2012-2366 is a data integrity vulnerability allowing remote authenticated users to overwrite database activity presets.
CVE-2012-2366 is present in Moodle versions 2.1.0 through 2.1.5 and 2.2.0 through 2.2.2.