Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-1168

25
FAUCET Score

CVE-2012-1168 describes a vulnerability in Moodle versions prior to 2.2.2 where updating a user profile without specifying a password would inadvertently reset the user's password. This flaw affects Moodle installations across various platforms, including Fedora and Red Hat Enterprise Linux. With a CVSS score of 8.2 (HIGH), this vulnerability presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to high integrity impact (password resets) and low availability impact. The absence of authentication requirements makes it easily exploitable. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered widespread attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.2.2CPE matchmatch criteria
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
15CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*
16CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
17CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.29%
Probability of exploitation in next 30 days
EPSS Percentile
81.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0229 is in the 67th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia nvd_reference
View patch

References

lists.fedoraproject.org / pipermail/package-announce/2012-April/077635.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2012-April/078209.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2012-April/078210.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2012-May/080712.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2012-May/081047.html
Mailing ListThird Party Advisory
access.redhat.com / security/cve/cve-2012-1168
Broken Link
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
moodle.org / mod/forum/discuss.php
Vendor Advisory
security-tracker.debian.org / tracker/CVE-2012-1168
Third Party Advisory