CVE-2011-4592
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
20/07/2012
Last modified:
11/04/2025
Description
The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:2.1.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://git.moodle.org/gw?p=moodle.git%3Ba%3Dcommit%3Bh%3Dade30ad3c420ce035a3d68287db701b70e806b3f
- http://moodle.org/mod/forum/discuss.php?d=191761
- https://bugzilla.redhat.com/show_bug.cgi?id=761248
- http://git.moodle.org/gw?p=moodle.git%3Ba%3Dcommit%3Bh%3Dade30ad3c420ce035a3d68287db701b70e806b3f
- http://moodle.org/mod/forum/discuss.php?d=191761
- https://bugzilla.redhat.com/show_bug.cgi?id=761248



