Arbitrary User Submission Comments Exposure in Moodle 2.3.x and 2.4.x

Arbitrary User Submission Comments Exposure in Moodle 2.3.x and 2.4.x

CVE-2012-6102 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:P/A:N

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.

Learn more about our User Device Pen Test.