CyberRota Analysis
AI analysis pending.
CVE
CVE-2012-4408
Severity
MEDIUM
CVSS
5.5
EPSS
1.13%
Original NVD Description
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.