CVE-2012-6104: Infoleak
Published Jan 27, 2013
·Updated
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
Affected Software
12 affected components
Moodle moodle=2.2.0
Moodle moodle=2.2.1
Moodle moodle=2.2.2
Moodle moodle=2.2.3
Moodle moodle=2.2.4
Moodle moodle=2.2.5
Moodle moodle=2.2.6
Moodle moodle=2.3.0
Moodle moodle=2.3.1
Moodle moodle=2.3.2
Moodle moodle=2.3.3
Moodle moodle=2.4.0
Event History
Jan 27, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6104?
CVE-2012-6104 is classified as a medium severity vulnerability.
2
How do I fix CVE-2012-6104?
To fix CVE-2012-6104, upgrade Moodle to version 2.2.7, 2.3.4, or 2.4.1 or later.
3
Who is affected by CVE-2012-6104?
CVE-2012-6104 affects Moodle versions 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1.
4
What type of vulnerability is CVE-2012-6104?
CVE-2012-6104 is an information disclosure vulnerability.
5
What can attackers do with CVE-2012-6104?
Attackers can exploit CVE-2012-6104 to obtain sensitive information from site-level blogs by leveraging the guest role.