CVE-2011-4584
 
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
La funcionalidad de autenticación MNET en Moodle v1.9.x antes de v1.9.15, v2.0.x antes de v2.0.6 y v2.1.x antes de v2.1.3 permite hacerse pasar por otras cuentas de usuario a usuarios remotos autenticados mediante el uso de la funcionalidad "Login As" junto con una funcionalidad remota de inicio de sesión único (Single-Sign-On), tal y como lo demuestra un sitio hecho con Mahara.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2011-11-29 CVE Reserved
- 2012-03-01 CVE Published
- 2023-06-10 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=10df8657c1c138c0d0ab1d4796c552fcec0c299b | X_refsource_confirm | |
https://bugzilla.redhat.com/show_bug.cgi?id=761248 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://moodle.org/mod/forum/discuss.php?d=191751 | 2023-02-13 | |
http://www.debian.org/security/2012/dsa-2421 | 2023-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.1 Search vendor "Moodle" for product "Moodle" and version "1.9.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.2 Search vendor "Moodle" for product "Moodle" and version "1.9.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.3 Search vendor "Moodle" for product "Moodle" and version "1.9.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.4 Search vendor "Moodle" for product "Moodle" and version "1.9.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.5 Search vendor "Moodle" for product "Moodle" and version "1.9.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.6 Search vendor "Moodle" for product "Moodle" and version "1.9.6" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.7 Search vendor "Moodle" for product "Moodle" and version "1.9.7" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.8 Search vendor "Moodle" for product "Moodle" and version "1.9.8" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.9 Search vendor "Moodle" for product "Moodle" and version "1.9.9" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.10 Search vendor "Moodle" for product "Moodle" and version "1.9.10" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.11 Search vendor "Moodle" for product "Moodle" and version "1.9.11" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.12 Search vendor "Moodle" for product "Moodle" and version "1.9.12" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.13 Search vendor "Moodle" for product "Moodle" and version "1.9.13" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 1.9.14 Search vendor "Moodle" for product "Moodle" and version "1.9.14" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.0 Search vendor "Moodle" for product "Moodle" and version "2.0.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.1 Search vendor "Moodle" for product "Moodle" and version "2.0.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.2 Search vendor "Moodle" for product "Moodle" and version "2.0.2" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.3 Search vendor "Moodle" for product "Moodle" and version "2.0.3" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.4 Search vendor "Moodle" for product "Moodle" and version "2.0.4" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.0.5 Search vendor "Moodle" for product "Moodle" and version "2.0.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.0 Search vendor "Moodle" for product "Moodle" and version "2.1.0" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.1 Search vendor "Moodle" for product "Moodle" and version "2.1.1" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | 2.1.2 Search vendor "Moodle" for product "Moodle" and version "2.1.2" | - |
Affected
|