4
CVSSv2

CVE-2012-2354

Published: 21/07/2012 Updated: 13/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Moodle 2.1.x prior to 2.1.6 and 2.2.x prior to 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.1.2

moodle moodle 2.1.1

moodle moodle 2.1.5

moodle moodle 2.1.3

moodle moodle 2.1.4

moodle moodle 2.1.0

moodle moodle 2.2.2

moodle moodle 2.2.1

moodle moodle 2.2.0