mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2012-07-21T01:00:00

Updated: 2024-08-06T19:34:25.210Z

Reserved: 2012-04-19T00:00:00

Link: CVE-2012-2366

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2012-07-21T03:38:56.470

Modified: 2020-12-01T14:43:58.053

Link: CVE-2012-2366

cve-icon Redhat

No data.