Vulnerability Name: | CVE-2011-4293 (CCN-77218) | ||||||||
Assigned: | 2011-08-08 | ||||||||
Published: | 2011-08-08 | ||||||||
Updated: | 2020-12-01 | ||||||||
Summary: | The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-4293 Source: CONFIRM Type: Patch http://git.moodle.org/gw?p=moodle.git;a=commit;h=e1c2a211f259821910be2cba23679d4176fb00a3 Source: CCN Type: MSA-11-0019 Themes writing to files outside Moodle data directory Source: CONFIRM Type: Vendor Advisory http://moodle.org/mod/forum/discuss.php?d=182736 Source: MLIST Type: UNKNOWN [oss-security] 20111113 Re: Fwd: DSA 2338-1 moodle security update Source: CCN Type: OSVDB ID: 84268 Moodle CSS Duplicate Caching File System Temporary Directory Write Source: XF Type: UNKNOWN moodle-theme-sec-bypass(77218) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |