CVE-2012-6098: Medium severity moodle vulnerability
grade/edit/outcome/editform.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6098?
CVE-2012-6098 is considered to have a medium severity due to unauthorized access to functionality that can manipulate custom outcomes.
How do I fix CVE-2012-6098?
To fix CVE-2012-6098, update your Moodle software to a version after 2.4.1 or apply the patch provided in the official Moodle repository.
Which versions of Moodle are affected by CVE-2012-6098?
CVE-2012-6098 affects Moodle versions 1.9.x up to 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1.
What types of attacks are possible due to CVE-2012-6098?
CVE-2012-6098 allows remote authenticated users to convert custom outcomes into standard ones, potentially leading to unauthorized data manipulation.
Is it safe to use Moodle versions affected by CVE-2012-6098?
Using affected versions of Moodle poses a security risk, so it is advisable to upgrade to a patched version as soon as possible.