Moderate severityNVD Advisory· Published Jul 16, 2012· Updated Apr 29, 2026
CVE-2011-4294
CVE-2011-4294
Description
The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | < 1.9.13 | 1.9.13 |
moodle/moodlePackagist | >= 2.0, < 2.0.4 | 2.0.4 |
moodle/moodlePackagist | >= 2.1, < 2.1.1 | 2.1.1 |
Affected products
18cpe:2.3:a:moodle:moodle:1.9.1:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:moodle:moodle:1.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.10:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.11:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.12:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.4:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.8:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:1.9.9:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
9- moodle.org/mod/forum/discuss.phpnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-hxmp-8f47-x9fcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-4294ghsaADVISORY
- git.moodle.org/gwghsaWEB
- openwall.com/lists/oss-security/2011/11/14/1nvdWEB
- github.com/moodle/moodle/commit/18c2fcf8f19e00f0e89421d8fd8b7486a6dc6f79ghsaWEB
- github.com/moodle/moodle/commit/417fdfab6bbdcfc3f5b64704ec06912ae9cd1050ghsaWEB
- github.com/moodle/moodle/commit/8f9f666c902cb30ef6f519353f38c45a29fdf4a6ghsaWEB
- git.moodle.org/gwnvd
News mentions
0No linked articles in our index yet.