Moderate severityNVD Advisory· Published Jul 11, 2012· Updated Jun 16, 2026
CVE-2011-4300
CVE-2011-4300
Description
The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 2.1, < 2.1.2 | 2.1.2 |
moodle/moodlePackagist | >= 2.0.0, < 2.0.5 | 2.0.5 |
Affected products
8cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:moodle:moodle:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:moodle:moodle:2.1.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- bugzilla.redhat.com/show_bug.cginvdPatchWEB
- moodle.org/mod/forum/discuss.phpnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-9p54-pc88-36c4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2011-4300ghsaADVISORY
- git.moodle.org/gwnvdWEB
- git.moodle.org/gwghsaWEB
- github.com/moodle/moodle/commit/6f7c43c7de8f62cd53a7f3b54ad5325cd109c1beghsaWEB
- github.com/moodle/moodle/commit/81c77993e3808bba68fe24d6bfbac19a41679a6fghsaWEB
- github.com/moodle/moodle/commit/f6b07c4da54a9db24723beb147e8a19a3d487e00ghsaWEB
News mentions
0No linked articles in our index yet.