CVE-2011-4584
20.07.2012, 10:40
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.Enginsight
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 1.9.1 |
| moodle | moodle | 1.9.2 |
| moodle | moodle | 1.9.3 |
| moodle | moodle | 1.9.4 |
| moodle | moodle | 1.9.5 |
| moodle | moodle | 1.9.6 |
| moodle | moodle | 1.9.7 |
| moodle | moodle | 1.9.8 |
| moodle | moodle | 1.9.9 |
| moodle | moodle | 1.9.10 |
| moodle | moodle | 1.9.11 |
| moodle | moodle | 1.9.12 |
| moodle | moodle | 1.9.13 |
| moodle | moodle | 1.9.14 |
| moodle | moodle | 2.0.0 |
| moodle | moodle | 2.0.1 |
| moodle | moodle | 2.0.2 |
| moodle | moodle | 2.0.3 |
| moodle | moodle | 2.0.4 |
| moodle | moodle | 2.0.5 |
| moodle | moodle | 2.1.0 |
| moodle | moodle | 2.1.1 |
| moodle | moodle | 2.1.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References