Release date:
Updated on:
Affected Systems:
Moodle Dropbox Repository File Picker
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-5471
Moodle is a course Management System (CMS), also known as Learning Management System (LMS) or virtual learning environment (VLE ).
The Dropbox Repository File Picker in Moodle 2.x has a security vulnerability. By using the unattended workstation, authenticated remote attackers can access applications with other user permissions.
<* Source: vendor
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-5471
Https://moodle.org/mod/forum/discuss.php? D = 216155
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
* Disable Dropbox Repository.
Vendor patch:
Moodle
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://moodle.org/mod/forum/