Vulnerability Name: | CVE-2012-6101 (CCN-81444) | ||||||||||||
Assigned: | 2012-12-06 | ||||||||||||
Published: | 2013-01-15 | ||||||||||||
Updated: | 2020-12-01 | ||||||||||||
Summary: | Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-6101 Source: CONFIRM Type: UNKNOWN http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-35991 Source: MLIST Type: UNKNOWN [oss-security] 20130121 Moodle security notifications public Source: CCN Type: SA51842 Moodle Multiple Vulnerabilities Source: CCN Type: BID-60058 Moodle CVE-2012-6101 Multiple URI Redirection Vulnerabilities Source: XF Type: UNKNOWN moodle-multiple-open-redirect(81444) Source: CCN Type: Moodle Web Site Moodle Source: CCN Type: MSA-13-0005 Potential phishing attack through URL redirects Source: CONFIRM Type: Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=220162 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |