CVE-2012-5479
Publication date 21 November 2012
Last updated 24 July 2024
Ubuntu priority
The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.
Status
Package | Ubuntu Release | Status |
---|---|---|
moodle | 14.04 LTS trusty | Not in release |
References
Other references
- https://moodle.org/mod/forum/discuss.php?d=216159
- http://openwall.com/lists/oss-security/2012/11/19/1
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36346
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-33791
- https://www.cve.org/CVERecord?id=CVE-2012-5479