{"id":"GHSA-w66h-c2vj-cm7f","summary":"Moodle Authentication Bypass in File Upload","details":"Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.","aliases":["CVE-2012-3387"],"modified":"2024-01-11T22:26:36.058936Z","published":"2022-05-13T01:12:59Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-11T22:06:32Z","nvd_published_at":"2012-07-23T21:55:00Z","cwe_ids":["CWE-287"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-3387"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/3b6629c088f14c6ee8f13a009ff27441d164f334"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/61a339e59857fd36080f4a468a16cd6a539d90bb"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/76954"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"https://web.archive.org/web/20121104220059/http://www.securityfocus.com/bid/54481"},{"type":"WEB","url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-33948"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2012/07/17/1"}],"affected":[{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3"},{"fixed":"2.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w66h-c2vj-cm7f/GHSA-w66h-c2vj-cm7f.json"}}],"schema_version":"1.9.0"}