PT-2012-2873 · Moodle+1 · Moodle+1

·

CVE-2012-0796

·

Publicado

2012-07-17

·

Atualizado

2023-02-13

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 1.9.x through 1.9.15 Moodle versions 2.0.x through 2.0.6 Moodle versions 2.1.x through 2.1.3 Moodle versions 2.2.x through 2.2.0
Description The issue allows remote authenticated users to inject arbitrary e-mail headers via crafted From: or Sender: headers. This can be achieved by manipulating the From: or Sender: header in the class.phpmailer.php file of the PHPMailer library. Arbitrary additional email headers can be injected via these crafted headers.
Recommendations For Moodle versions 1.9.x through 1.9.15, update to version 1.9.16 or later. For Moodle versions 2.0.x through 2.0.6, update to version 2.0.7 or later. For Moodle versions 2.1.x through 2.1.3, update to version 2.1.4 or later. For Moodle versions 2.2.x through 2.2.0, update to version 2.2.1 or later. As a temporary workaround, filter user-supplied values prior to using them in From or Sender properties.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0796
DSA-2421-1
GHSA-398J-F7M7-795J

Produtos afetados

Moodle
Phpmailer