Vulnerability Name: | CVE-2011-4285 (CCN-65893) | ||||||||
Assigned: | 2011-03-01 | ||||||||
Published: | 2011-03-01 | ||||||||
Updated: | 2020-12-01 | ||||||||
Summary: | The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-4285 Source: CONFIRM Type: Patch http://git.moodle.org/gw?p=moodle.git;a=commit;h=5cfe8aecb8b78e343ded38ba9e7a0a859887d21c Source: CCN Type: Moodle Web site Moodle.org: open-source community-based tools for learning Source: CCN Type: MSA-11-0010 Incorrect default for mod:course/delete capability in teacher role Source: CONFIRM Type: Vendor Advisory http://moodle.org/mod/forum/discuss.php?d=170011 Source: MLIST Type: UNKNOWN [oss-security] 20111113 Re: Fwd: DSA 2338-1 moodle security update Source: CCN Type: SA43570 Moodle Multiple Vulnerabilities Source: CCN Type: OSVDB ID: 75062 Moodle teacher Role Permissions Weakness Arbitrary Course Deletion Source: CCN Type: BID-46646 Moodle Prior to 1.9.11/2.0.2 Multiple Vulnerabilities Source: XF Type: UNKNOWN moodle-teacher-sec-bypass(65893) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |