CVE-2012-3392: Medium severity Moodle moodle vulnerability
mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3392?
CVE-2012-3392 has a moderate severity rating as it allows remote authenticated users to unsubscribe from mandatory forums.
How do I fix CVE-2012-3392?
To fix CVE-2012-3392, upgrade Moodle to version 2.1.7 or 2.2.4 or later.
What versions of Moodle are affected by CVE-2012-3392?
CVE-2012-3392 affects Moodle versions 2.1.0 to 2.1.6 and 2.2.0 to 2.2.3.
What impact does CVE-2012-3392 have on Moodle users?
CVE-2012-3392 allows users with the student role to bypass forum-subscription requirements, leading to potential loss of engagement in key discussions.
Is it safe to use Moodle versions prior to the fix for CVE-2012-3392?
Using Moodle versions prior to the fix for CVE-2012-3392 poses a security risk as it may allow unauthorized changes to forum subscriptions.