SB2012071601 - Multiple vulnerabilities in Moodle 



SB2012071601 - Multiple vulnerabilities in Moodle

Published: July 16, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012071601
Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 60% Low 40%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2011-4293)

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.


2) Input validation error (CVE-ID: CVE-2011-4294)

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.


3) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2011-4295)

The vulnerability allows a remote #AU# to read and manipulate data.

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.


4) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2011-4296)

The vulnerability allows a remote #AU# to manipulate or delete data.

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.


5) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2011-4297)

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.


Remediation

Install update from vendor's website.