lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
References
Configurations
History
21 Nov 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37244 - | |
References | () http://openwall.com/lists/oss-security/2013/01/21/1 - | |
References | () https://moodle.org/mod/forum/discuss.php?d=220163 - Vendor Advisory |
Information
Published : 2013-01-27 22:55
Updated : 2024-11-21 01:45
NVD link : CVE-2012-6102
Mitre link : CVE-2012-6102
CVE.ORG link : CVE-2012-6102
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-264
Permissions, Privileges, and Access Controls