Lucene search

K
nvd[email protected]NVD:CVE-2011-4589
HistoryJul 20, 2012 - 10:40 a.m.

CVE-2011-4589

2012-07-2010:40:36
CWE-264
web.nvd.nist.gov
3

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

64.4%

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.

Affected configurations

Nvd
Node
moodlemoodleMatch2.0.0
OR
moodlemoodleMatch2.0.1
OR
moodlemoodleMatch2.0.2
OR
moodlemoodleMatch2.0.3
OR
moodlemoodleMatch2.0.4
OR
moodlemoodleMatch2.0.5
Node
moodlemoodleMatch2.1.0
OR
moodlemoodleMatch2.1.1
OR
moodlemoodleMatch2.1.2

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

64.4%