4.9
CVSSv2

CVE-2012-4402

Published: 19/09/2012 Updated: 01/12/2020
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

webservice/lib.php in Moodle 2.1.x prior to 2.1.8, 2.2.x prior to 2.2.5, and 2.3.x prior to 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.1.3

moodle moodle 2.1.7

moodle moodle 2.1.1

moodle moodle 2.1.0

moodle moodle 2.1.5

moodle moodle 2.1.4

moodle moodle 2.1.2

moodle moodle 2.1.6

moodle moodle 2.2.4

moodle moodle 2.2.0

moodle moodle 2.2.3

moodle moodle 2.2.2

moodle moodle 2.2.1

moodle moodle 2.3.1

moodle moodle 2.3.0