CVE-2012-3394: Infoleak
auth/ldap/ntlmssoattempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3394?
CVE-2012-3394 is considered a medium severity vulnerability due to its potential for sensitive information exposure.
How do I fix CVE-2012-3394?
To fix CVE-2012-3394, upgrade Moodle to versions 2.0.10, 2.1.7, 2.2.4, or 2.3.1 or later.
What types of attacks can exploit CVE-2012-3394?
CVE-2012-3394 can be exploited through man-in-the-middle attacks that allow attackers to intercept sensitive information.
Which versions of Moodle are affected by CVE-2012-3394?
Moodle versions 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 are affected by CVE-2012-3394.
What is the impact of CVE-2012-3394?
The impact of CVE-2012-3394 includes the risk of exposing sensitive user data during LDAP authentication due to unsecure HTTP redirection.