CVE-2012-3388: Medium severity Moodle moodle vulnerability
The isenrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Remote authenticated users are the relevant attacker population. The issue affects Moodle 2.2.x before 2.2.4 and Moodle 2.3.x before 2.3.1.
What conditions are required for exploitation?
Exploitation requires an authenticated Moodle account and unspecified actions that cause a user record to be cached. The flaw can then bypass an intended capability check.
What remediation is identified?
Upgrade Moodle 2.2.x to 2.2.4 or later, or Moodle 2.3.x to 2.3.1 or later. The provided data does not identify a workaround for systems that cannot be upgraded immediately.