CVE-2012-5481: Medium severity moodle vulnerability
Published Nov 21, 2012
·Updated
Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.
Affected Software
3 affected components
Moodle moodle=2.3.0
Moodle moodle=2.3.1
Moodle moodle=2.3.2
Event History
Nov 21, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5481?
CVE-2012-5481 has been classified as a moderate severity vulnerability due to its potential to expose sensitive capability data.
2
How do I fix CVE-2012-5481?
To fix CVE-2012-5481, upgrade your Moodle instance to version 2.3.3 or later.
3
Who is affected by CVE-2012-5481?
CVE-2012-5481 affects all installations of Moodle versions 2.3.0 to 2.3.2.
4
What type of attack does CVE-2012-5481 exploit?
CVE-2012-5481 allows remote authenticated users to bypass role management capabilities.
5
What data is at risk with CVE-2012-5481?
CVE-2012-5481 exposes all capability data to users who are normally restricted from accessing it.