CVE-2012-4402: Medium severity moodle vulnerability
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4402?
CVE-2012-4402 has a severity rating of medium due to its potential to allow unauthorized access to external service functions.
How do I fix CVE-2012-4402?
To fix CVE-2012-4402, upgrade Moodle to version 2.1.8, 2.2.5, or 2.3.2 or later.
Which versions of Moodle are affected by CVE-2012-4402?
Versions of Moodle from 2.1.0 to 2.1.7, 2.2.0 to 2.2.4, and 2.3.0 to 2.3.1 are affected by CVE-2012-4402.
What does CVE-2012-4402 exploit?
CVE-2012-4402 exploits improper restrictions on web-service tokens, allowing unauthorized function execution.
Who can be targeted by CVE-2012-4402?
CVE-2012-4402 targets remote authenticated users who have access to web-service tokens.