Publish GHSA-j3x5-cwfj-pfcw

This commit is contained in:
advisory-database[bot]
2025-04-12 02:38:24 +00:00
parent fb5e3eaa2d
commit 71b27b8628
@@ -1,19 +1,49 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3x5-cwfj-pfcw",
"modified": "2025-04-11T03:59:16Z",
"modified": "2025-04-12T02:35:07Z",
"published": "2022-05-13T01:13:17Z",
"aliases": [
"CVE-2011-4287"
],
"summary": "Moodle does not force password changes for autosubscribed users",
"details": "admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.",
"severity": [],
"affected": [],
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "moodle/moodle"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4287"
},
{
"type": "PACKAGE",
"url": "http://git.moodle.org"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=22a77963439e00441949440f0517135b3a5418da"
@@ -32,10 +62,12 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-263"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2025-04-12T02:35:07Z",
"nvd_published_at": "2012-07-16T10:28:00Z"
}
}