CVE-2012-6105: Infoleak
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6105?
CVE-2012-6105 has been classified as a medium severity vulnerability.
How do I fix CVE-2012-6105?
To resolve CVE-2012-6105, you should upgrade to Moodle versions 2.1.10, 2.2.7, 2.3.4, or 2.4.1 or later.
What types of attack are possible with CVE-2012-6105?
CVE-2012-6105 allows remote attackers to access sensitive information via an RSS feed even when blogging is disabled.
Which versions of Moodle are affected by CVE-2012-6105?
CVE-2012-6105 affects Moodle versions 2.1.x prior to 2.1.10, 2.2.x prior to 2.2.7, 2.3.x prior to 2.3.4, and 2.4.x prior to 2.4.1.
What does CVE-2012-6105 expose to attackers?
CVE-2012-6105 exposes sensitive blog feed information to attackers despite the blog feature being disabled.