mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://docs.moodle.org/en/Moodle_1.9.7_release_notes | patch |
http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.16.2.10&r2=1.16.2.11 | patch |
http://docs.moodle.org/en/Moodle_1.8.11_release_notes | patch |
http://moodle.org/mod/forum/discuss.php?d=139106 | patch vendor advisory |
http://cvs.moodle.org/moodle/mnet/lib.php?r1=1.9.2.7&r2=1.9.2.8 | patch |
http://www.vupen.com/english/advisories/2009/3455 | vdb entry vendor advisory |
http://secunia.com/advisories/37614 | third party advisory vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00730.html | vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00704.html | vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00751.html | vendor advisory |
http://www.securityfocus.com/bid/37244 | patch vdb entry |