CVE-2012-6102

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.3.3:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:moodle:moodle:2.4.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:45

Type Values Removed Values Added
References () http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37244 - () http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37244 -
References () http://openwall.com/lists/oss-security/2013/01/21/1 - () http://openwall.com/lists/oss-security/2013/01/21/1 -
References () https://moodle.org/mod/forum/discuss.php?d=220163 - Vendor Advisory () https://moodle.org/mod/forum/discuss.php?d=220163 - Vendor Advisory

Information

Published : 2013-01-27 22:55

Updated : 2024-11-21 01:45


NVD link : CVE-2012-6102

Mitre link : CVE-2012-6102

CVE.ORG link : CVE-2012-6102


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-264

Permissions, Privileges, and Access Controls