Unrated severityNVD Advisory· Published Sep 19, 2012· Updated Apr 29, 2026
CVE-2012-4403
CVE-2012-4403
Description
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- moodle.org/mod/forum/discuss.phpnvdVendor Advisory
- openwall.com/lists/oss-security/2012/09/17/1nvd
News mentions
0No linked articles in our index yet.