GHSA-9p54-pc88-36c4
Dashboard / Vulnerabilities / GHSA-9p54-pc88-36c4
Summary: Moodle does not properly restrict access to category and course data
Details: The `file_browser` component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.
References: https://nvd.nist.gov/vuln/detail/CVE-2011-4300, https://github.com/moodle/moodle/commit/6f7c43c7de8f62cd53a7f3b54ad5325cd109c1be, https://github.com/moodle/moodle/commit/81c77993e3808bba68fe24d6bfbac19a41679a6f, https://github.com/moodle/moodle/commit/f6b07c4da54a9db24723beb147e8a19a3d487e00, https://bugzilla.redhat.com/show_bug.cgi?id=747444, https://github.com/moodle/moodle, http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=f6b07c4da54a9db24723beb147e8a19a3d487e00, http://git.moodle.org/gw?p=moodle.git;a=commit;h=f6b07c4da54a9db24723beb147e8a19a3d487e00, http://moodle.org/mod/forum/discuss.php?d=188311
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: ECOSYSTEM
Events:
