5
CVSSv2

CVE-2012-4403

Published: 19/09/2012 Updated: 01/12/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

theme/yui_combo.php in Moodle 2.3.x prior to 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote malicious users to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.3.0

moodle moodle 2.3.1