CVE-2012-0801
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://moodle.org/mod/forum/discuss.php?d=194020
References
- http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=51070abc78b9e1db1db9a44855e8623b22bebd48
- http://moodle.org/mod/forum/discuss.php?d=194020
- https://bugzilla.redhat.com/show_bug.cgi?id=783532
- http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=51070abc78b9e1db1db9a44855e8623b22bebd48
- http://moodle.org/mod/forum/discuss.php?d=194020
- https://bugzilla.redhat.com/show_bug.cgi?id=783532
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.