UBUNTU-CVE-2012-6101

Source
https://ubuntu.com/security/CVE-2012-6101
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-6101.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2012-6101
Upstream
  • CVE-2012-6101
Withdrawn
2025-07-18T16:42:48Z
Published
2013-01-27T22:55:00Z
Modified
2025-07-16T07:17:03Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php.

References

Affected packages

Ubuntu:14.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle@2.5.4-1ubuntu1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.5.4-1ubuntu1

Affected versions

2.*
2.5.2-1
2.5.3-1
2.5.3-2
2.5.3-3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "moodle",
            "binary_version": "2.5.4-1ubuntu1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-6101.json"