Description
The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.
References (3)
Core 3
Core References
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2011/11/14/1
Vendor Advisory x_refsource_confirm
http://moodle.org/mod/forum/discuss.php?d=182736
Patch x_refsource_confirm
http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=e1c2a211f259821910be2cba23679d4176fb00a3
Scores
EPSS
0.0019
EPSS Percentile
41.0%
Details
CWE
CWE-264
Status
published
Products (6)
moodle/moodle
2.0.0
moodle/moodle
2.0.1
moodle/moodle
2.0.2
moodle/moodle
2.0.3
moodle/moodle
2.1.0
moodle/moodle
2.0 - 2.0.4Packagist
Published
Jul 16, 2012
Tracked Since
Feb 18, 2026