CVE-2011-4287

Moodle 2.0.x <2.0.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.

References (3)

Core 3

Scores

EPSS 0.0049
EPSS Percentile 65.6%

Details

CWE
CWE-264
Status published
Products (4)
moodle/moodle 2.0.0
moodle/moodle 2.0.1
moodle/moodle 2.0.2
moodle/moodle 2.0.0 - 2.0.2Packagist
Published Jul 16, 2012
Tracked Since Feb 18, 2026