CVE-2012-6104

EUVD-2012-5973
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
moodlemoodle
2.2.0
moodlemoodle
2.2.1
moodlemoodle
2.2.2
moodlemoodle
2.2.3
moodlemoodle
2.2.4
moodlemoodle
2.2.5
moodlemoodle
2.2.6
moodlemoodle
2.3.0
moodlemoodle
2.3.1
moodlemoodle
2.3.2
moodlemoodle
2.3.3
moodlemoodle
2.4.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
moodle
hardy
ignored
lucid
not-affected
oneiric
not-affected
precise
not-affected
quantal
ignored
raring
ignored
saucy
not-affected
trusty
dne