Vulnerability Name: | CVE-2011-4287 (CCN-67553) | ||||||||
Assigned: | 2011-05-18 | ||||||||
Published: | 2011-05-18 | ||||||||
Updated: | 2020-12-01 | ||||||||
Summary: | admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-4287 Source: CONFIRM Type: Patch http://git.moodle.org/gw?p=moodle.git;a=commit;h=22a77963439e00441949440f0517135b3a5418da Source: CCN Type: Moodle Web site Moodle.org: open-source community-based tools for learning Source: CONFIRM Type: Vendor Advisory http://moodle.org/mod/forum/discuss.php?d=175588 Source: CCN Type: MSA-11-0012 Authentication issue Source: MLIST Type: UNKNOWN [oss-security] 20111113 Re: Fwd: DSA 2338-1 moodle security update Source: CCN Type: SA44630 Moodle Multiple Vulnerabilities Source: CCN Type: OSVDB ID: 84270 Moodle admin/uploaduser_form.php Autosubcribed User Default Password Source: CCN Type: BID-47920 Moodle Prior to 1.9.12/2.0.3 Multiple Security Vulnerabilities Source: XF Type: UNKNOWN moodle-csv-security-bypass(67553) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |