5.8
CVSSv2

CVE-2011-4294

Published: 16/07/2012 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The error-message functionality in Moodle 1.9.x prior to 1.9.13, 2.0.x prior to 2.0.4, and 2.1.x prior to 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow malicious users to trick users into visiting arbitrary web sites via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.0.2

moodle moodle 1.9.4

moodle moodle 1.9.1

moodle moodle 1.9.6

moodle moodle 1.9.9

moodle moodle 2.0.1

moodle moodle 1.9.11

moodle moodle 1.9.2

moodle moodle 1.9.12

moodle moodle 1.9.10

moodle moodle 2.0.3

moodle moodle 1.9.3

moodle moodle 1.9.5

moodle moodle 1.9.8

moodle moodle 1.9.7

moodle moodle 2.0.0

moodle moodle 2.1.0