7.5

CVE-2012-1155

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moodle ≫ Moodle Version >= 1.9 < 1.9.17
Moodle ≫ Moodle Version >= 2.0 < 2.0.8
Moodle ≫ Moodle Version >= 2.1 < 2.1.5
Moodle ≫ Moodle Version >= 2.2 < 2.2.2
Fedoraproject ≫ Fedora Version 15
Fedoraproject ≫ Fedora Version 16
Fedoraproject ≫ Fedora Version 17
Redhat ≫ Enterprise Linux Version 6.0
Debian ≫ Debian Linux Version 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.14% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html
Third Party Advisory
Mailing List
https://access.redhat.com/security/cve/cve-2012-1155
Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1155
Patch
Third Party Advisory
Issue Tracking
https://moodle.org/mod/forum/discuss.php?d=198621
Patch
Vendor Advisory
https://security-tracker.debian.org/tracker/CVE-2012-1155
Third Party Advisory