5.5
CVSSv2

CVE-2012-3392

Published: 23/07/2012 Updated: 01/12/2020
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

mod/forum/unsubscribeall.php in Moodle 2.1.x prior to 2.1.7 and 2.2.x prior to 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.1.3

moodle moodle 2.1.0

moodle moodle 2.2.3

moodle moodle 2.2.2

moodle moodle 2.1.5

moodle moodle 2.1.4

moodle moodle 2.2.1

moodle moodle 2.2.0

moodle moodle 2.1.2

moodle moodle 2.1.6

moodle moodle 2.1.1