LWN.net Logo

moodle: unintended Dropbox access

Package(s):moodle CVE #(s):CVE-2012-5471
Created:November 28, 2012 Updated:November 28, 2012
Description: From the CVE entry:

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

Alerts:
Fedora FEDORA-2012-18525 2012-11-28
Fedora FEDORA-2012-18570 2012-11-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds