AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2012-3388

MEDIUM · CVSS 4 EPSS 1.13%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-07-23 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-3388
Severity
MEDIUM
CVSS
4
EPSS
1.13%

Original Filing — NVD Description

The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.