René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

180 lines
6.4 KiB
JSON

{
"id": "CVE-2011-4301",
"sourceIdentifier": "secalert@redhat.com",
"published": "2012-07-11T10:26:10.860",
"lastModified": "2023-02-13T04:32:47.900",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields."
},
{
"lang": "es",
"value": "La clase MoodleQuickForm en la biblioteca de formularios en lib/formslib.php en Moodle v1.9.x antes de v1.9.14, v2.0.x antes de v2.0.5 y v2.1.x antes de v2.1.2 no reconoce las operaciones setConstant de Forms API, lo que permite a atacantes remotos presentar el contenido de forma inesperada mediante la modificaci\u00f3n de los valores de los campos constantes."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 5.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.2:*:*:*:*:*:*:*",
"matchCriteriaId": "D7F24649-B67F-4809-9F54-7B623AEF5A4A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.3:*:*:*:*:*:*:*",
"matchCriteriaId": "6B81655E-C3B5-4115-A4C4-B7AC2FCDAB7F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.4:*:*:*:*:*:*:*",
"matchCriteriaId": "ED9C3840-66BE-47EC-9F0C-E9D2171FF0B2"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.5:*:*:*:*:*:*:*",
"matchCriteriaId": "DBD062EB-1B1F-4DC8-A4F9-C2EC7D401E9D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.6:*:*:*:*:*:*:*",
"matchCriteriaId": "291F73E9-1059-4E7F-860F-0DF2A35AA456"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.7:*:*:*:*:*:*:*",
"matchCriteriaId": "0EB5859E-0996-46B5-BB44-34BD6EACBCF5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.8:*:*:*:*:*:*:*",
"matchCriteriaId": "F87F6707-99AB-478A-909D-1D87298D5514"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.9:*:*:*:*:*:*:*",
"matchCriteriaId": "4BCE8B26-58BB-471C-B291-E6AE22B96C5B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.10:*:*:*:*:*:*:*",
"matchCriteriaId": "768CE5AF-955B-4148-998A-A46BBDBA618B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.11:*:*:*:*:*:*:*",
"matchCriteriaId": "4283440F-9B21-4CE9-81FF-79DF3DEDCEE7"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.12:*:*:*:*:*:*:*",
"matchCriteriaId": "A989FADA-89C3-472B-86BF-0630D1CBBCA8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:1.9.13:*:*:*:*:*:*:*",
"matchCriteriaId": "4FAF84CB-46F1-4F37-BBAC-1CED0600B5B0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "DD248A1D-CACC-4E76-925A-078B736442AE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.1:*:*:*:*:*:*:*",
"matchCriteriaId": "9B8A0403-0869-495F-B7C0-13A387549C7A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.2:*:*:*:*:*:*:*",
"matchCriteriaId": "39791F43-CF89-485B-AA8B-634C282BB025"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.3:*:*:*:*:*:*:*",
"matchCriteriaId": "428E4846-8C9E-4592-8437-88FCDCED704D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.0.4:*:*:*:*:*:*:*",
"matchCriteriaId": "A4096977-3258-48B0-9C7B-D43FBC8BB1EA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "18C6F348-DAE9-4440-8B3A-8D92ADC6606F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:moodle:moodle:2.1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "367537BF-CBDF-4CBB-91B4-6E5A567EF605"
}
]
}
]
}
],
"references": [
{
"url": "http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=f1f70bd4dde6cd1ea4bdb8ab28fa3d36a53b89d8",
"source": "secalert@redhat.com"
},
{
"url": "http://moodle.org/mod/forum/discuss.php?d=188313",
"source": "secalert@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=747444",
"source": "secalert@redhat.com"
}
]
}