Release date:
Updated on:
Affected Systems:
Moodle 2.x
Unaffected system:
Moodle 2.2.3
Moodle 2.1.6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53629
Cve id: CVE-2012-2353, CVE-2012-2354, CVE-2012-2355, CVE-2012-2356
Moodle is a course Management System (CMS), also known as Learning Management System (LMS) or virtual learning environment (VLE ). It is a free web application. Teachers can use it to build efficient online learning websites.
Multiple Information Leakage and security restriction bypass vulnerabilities exist in the implementation of Moodle. Attackers can exploit these vulnerabilities to obtain sensitive information and bypass certain security restrictions.
<* Source: Andreas Grupp
Link: http://moodle.org/mod/forum/discuss.php? D = 203041
Http://moodle.org/mod/forum/discuss.php? D = 203042
Http://moodle.org/mod/forum/discuss.php? D = 203043
Http://moodle.org/mod/forum/discuss.php? D = 203044
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Moodle
------
Moodle has released a Security Bulletin (MSA-12-0027) and patches for this:
MSA-12-0027: Question bank capability issues
Link: http://moodle.org/mod/forum/discuss.php? D = 203044