CVE-2012-0797

Moodle <2.0.7, <2.1.4, <2.2.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

References (3)

Core 3
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=783532
Vendor Advisory x_refsource_confirm
http://moodle.org/mod/forum/discuss.php?d=194016

Scores

EPSS 0.0014
EPSS Percentile 34.2%

Details

CWE
CWE-16
Status published
Products (3)
moodle/moodle 2.2.0
moodle/moodle 2.0 - 2.0.6
moodle/moodle 2.2 - 2.2.1Packagist
Published Jul 17, 2012
Tracked Since Feb 18, 2026