CVE-2011-4287
Published Jul 16, 2012
Last updated a year ago
Overview
- Description
- admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD248A1D-CACC-4E76-925A-078B736442AE" }, { "criteria": "cpe:2.3:a:moodle:moodle:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B8A0403-0869-495F-B7C0-13A387549C7A" }, { "criteria": "cpe:2.3:a:moodle:moodle:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39791F43-CF89-485B-AA8B-634C282BB025" } ], "operator": "OR" } ] } ]