|
|
| |
|
| |
moodle: multiple vulnerabilities
| Package(s): | moodle |
CVE #(s): | CVE-2012-4401
CVE-2012-4407
|
| Created: | September 27, 2012 |
Updated: | October 3, 2012 |
| Description: |
From the Red Hat bugzilla entries [1, 2]:
CVE-2012-4401:
A security flaw was found in the way Moodle course management system performed user permissions validation by course topic management. A remote attackers, with course editing capabilities, but without ability to show / hide topics or set the current topic for a particular course could use this flaw to successfully complete these actions under certain circumstances.
CVE-2012-4407: A security flaw was found in the way file serving functionality of Moodle course management system enforced file access restrictions on blog post(s). A remote attacker could use this flaw to deliver files embedded as part of a blog without the publication state to be checked properly.
|
| Alerts: |
|
( Log in to post comments)
|
|
|