CVE-2012-5473: Infoleak
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5473?
CVE-2012-5473 has a moderate severity level due to its potential to expose sensitive activity entries to unauthorized users.
How do I fix CVE-2012-5473?
To fix CVE-2012-5473, upgrade Moodle to version 2.1.9, 2.2.6, or 2.3.3 or later.
Which versions of Moodle are affected by CVE-2012-5473?
CVE-2012-5473 affects Moodle versions 2.1.x prior to 2.1.9, 2.2.x prior to 2.2.6, and 2.3.x prior to 2.3.3.
What types of users are impacted by CVE-2012-5473?
Remote authenticated users can access activity entries of other groups due to the vulnerability in CVE-2012-5473.
Is there a workaround for CVE-2012-5473 if I cannot immediately upgrade?
There is no documented workaround for CVE-2012-5473, and upgrading is the recommended approach to mitigate the risk.