CVE-2012-6106: Medium severity moodle vulnerability
Published Jan 27, 2013
·Updated
calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object.
Affected Software
1 affected component
Moodle moodle=2.4.0
Event History
Jan 27, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6106?
CVE-2012-6106 has a low severity rating, primarily affecting authenticated users' permissions.
2
How do I fix CVE-2012-6106?
To fix CVE-2012-6106, upgrade Moodle to version 2.4.1 or later.
3
Which versions of Moodle are affected by CVE-2012-6106?
CVE-2012-6106 affects Moodle 2.4.0 and earlier versions.
4
What kind of attack does CVE-2012-6106 allow?
CVE-2012-6106 allows remote authenticated users to remove course-level calendar subscriptions.
5
Who is impacted by the vulnerability CVE-2012-6106?
Users with the student role in Moodle are impacted by CVE-2012-6106.