Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-3387

Опубликовано: 23 июл. 2012
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:moodle:moodle:2.3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.01128
Низкий

4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 14 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

debian
около 14 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether re ...

github
около 4 лет назад

Moodle Authentication Bypass in File Upload

EPSS

Процентиль: 63%
0.01128
Низкий

4 Medium

CVSS2

Дефекты

CWE-264