CVE-2012-3387: Medium severity Moodle moodle vulnerability
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.
Affected Software
Event History
Frequently Asked Questions
Which Moodle deployments are affected?
Moodle 2.3.x installations earlier than 2.3.1 are affected. The issue concerns file-upload handling where alias or shortcut references are intended to be restricted.
What access does an attacker need to exploit this issue?
An attacker must be remotely authenticated to Moodle and able to submit a file upload using a client that omits the client-side reference-permission check. No separate authentication bypass is described.
What is the remediation?
Upgrade Moodle to 2.3.1 or later within the 2.3.x branch. The provided data does not describe a server-side workaround if upgrading cannot be done immediately.