Skip to main content

Configuration

CVE-2012-3392

Severity Medium
Score 5.5/10

Summary

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

  • LOW
  • NETWORK
  • SINGLE
  • PARTIAL
  • NONE
  • PARTIAL

CWE-16 - Configuration

Weaknesses in this category are typically introduced during the configuration of the software.

References

Advisory Timeline

  • Published