GHSA-mpjx-8phj-5m34

Suggest an improvement
Source
https://github.com/advisories/GHSA-mpjx-8phj-5m34
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mpjx-8phj-5m34/GHSA-mpjx-8phj-5m34.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mpjx-8phj-5m34
Aliases
  • CVE-2012-5471
Published
2022-05-13T01:13:01Z
Modified
2024-01-11T23:41:37.746979Z
Summary
Moodle Allows Unauthenticated Dropbox Access
Details

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

Database specific
{
    "nvd_published_at": "2012-11-21T12:55:00Z",
    "cwe_ids": [
        "CWE-287"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-11T23:03:09Z"
}
References

Affected packages

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.3
Fixed
2.3.3

Database specific

{
    "last_known_affected_version_range": "<= 2.3.2"
}

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2
Fixed
2.2.6

Database specific

{
    "last_known_affected_version_range": "<= 2.2.5"
}

Packagist / moodle/moodle

Package

Name
moodle/moodle
Purl
pkg:composer/moodle/moodle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1
Fixed
2.1.9

Database specific

{
    "last_known_affected_version_range": "<= 2.1.8"
}