The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-07-11T10:00:00Z

Updated: 2024-08-07T00:01:51.637Z

Reserved: 2011-11-04T00:00:00Z

Link: CVE-2011-4300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2012-07-11T10:26:10.797

Modified: 2024-11-21T01:32:11.423

Link: CVE-2011-4300

cve-icon Redhat

No data.