#VU43829 Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4592 

 

#VU43829 Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4592

Published: July 20, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43829
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2011-4592
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Moodle
Software vendor:
moodle.org

Description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.


Remediation

Install update from vendor's website.

External links