CVE-2012-1160

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html Third Party Advisory
https://access.redhat.com/security/cve/cve-2012-1160 Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1160 Issue Tracking Patch Third Party Advisory
https://moodle.org/mod/forum/discuss.php?d=198629 Patch Vendor Advisory
https://security-tracker.debian.org/tracker/CVE-2012-1160 Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html Third Party Advisory
https://access.redhat.com/security/cve/cve-2012-1160 Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1160 Issue Tracking Patch Third Party Advisory
https://moodle.org/mod/forum/discuss.php?d=198629 Patch Vendor Advisory
https://security-tracker.debian.org/tracker/CVE-2012-1160 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*

History

21 Nov 2024, 01:36

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html - Third Party Advisory () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html - Third Party Advisory
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html - Third Party Advisory () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html - Third Party Advisory
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html - Third Party Advisory () http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html - Third Party Advisory
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html - Third Party Advisory () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html - Third Party Advisory
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html - Third Party Advisory () http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html - Third Party Advisory
References () https://access.redhat.com/security/cve/cve-2012-1160 - Broken Link () https://access.redhat.com/security/cve/cve-2012-1160 - Broken Link
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1160 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1160 - Issue Tracking, Patch, Third Party Advisory
References () https://moodle.org/mod/forum/discuss.php?d=198629 - Patch, Vendor Advisory () https://moodle.org/mod/forum/discuss.php?d=198629 - Patch, Vendor Advisory
References () https://security-tracker.debian.org/tracker/CVE-2012-1160 - Third Party Advisory () https://security-tracker.debian.org/tracker/CVE-2012-1160 - Third Party Advisory

Information

Published : 2019-11-14 17:15

Updated : 2024-11-21 01:36


NVD link : CVE-2012-1160

Mitre link : CVE-2012-1160

CVE.ORG link : CVE-2012-1160


JSON object : View

Products Affected

fedoraproject

  • fedora

moodle

  • moodle
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource