CVE-2012-3387

Moodle 2.3.x < 2.3.1 - Authenticated File Upload Restriction Bypass

Title source: llm
STIX 2.1

Description

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49890
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/76954
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2012/07/17/1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/54481

Scores

EPSS 0.0020
EPSS Percentile 41.6%

Details

CWE
CWE-264
Status published
Products (2)
moodle/moodle 2.3.0
moodle/moodle 2.3 - 2.3.1Packagist
Published Jul 23, 2012
Tracked Since Feb 18, 2026