admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 01:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=0f75e1e6272db0303abc8e27362e5c3a1344b82f - | |
References | () http://openwall.com/lists/oss-security/2012/05/23/2 - |
Information
Published : 2012-07-21 03:38
Updated : 2024-11-21 01:38
NVD link : CVE-2012-2359
Mitre link : CVE-2012-2359
CVE.ORG link : CVE-2012-2359
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-264
Permissions, Privileges, and Access Controls