CVE-2012-3388
N/A
N/A
Summary
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76955
- http://secunia.com/advisories/49890
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-33916
- http://openwall.com/lists/oss-security/2012/07/17/1
- http://www.securityfocus.com/bid/54481
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76955
- http://secunia.com/advisories/49890
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-33916
- http://openwall.com/lists/oss-security/2012/07/17/1
- http://www.securityfocus.com/bid/54481
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.