LWN.net Logo

moodle: multiple vulnerabilities

Package(s):moodle CVE #(s):CVE-2012-4401 CVE-2012-4407
Created:September 27, 2012 Updated:October 3, 2012
Description:

From the Red Hat bugzilla entries [1, 2]:

CVE-2012-4401: A security flaw was found in the way Moodle course management system performed user permissions validation by course topic management. A remote attackers, with course editing capabilities, but without ability to show / hide topics or set the current topic for a particular course could use this flaw to successfully complete these actions under certain circumstances.

CVE-2012-4407: A security flaw was found in the way file serving functionality of Moodle course management system enforced file access restrictions on blog post(s). A remote attacker could use this flaw to deliver files embedded as part of a blog without the publication state to be checked properly.

Alerts:
Fedora FEDORA-2012-14348 2012-09-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds