CVE-2012-1168 describes a vulnerability in Moodle versions prior to 2.2.2 where updating a user profile without specifying a password would inadvertently reset the user's password. This flaw affects Moodle installations across various platforms, including Fedora and Red Hat Enterprise Linux. With a CVSS score of 8.2 (HIGH), this vulnerability presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to high integrity impact (password resets) and low availability impact. The absence of authentication requirements makes it easily exploitable. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.2CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
15CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:* | ||
16CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:* | ||
17CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.