Back to Database
Status published
High
CVE-2012-1168
Moodle before 2.2.2 has a password and web services issue...
Vulnerability Description
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-1168
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html
- https://security-tracker.debian.org/tracker/CVE-2012-1168
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1168
- https://access.redhat.com/security/cve/cve-2012-1168
- http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html
- https://moodle.org/mod/forum/discuss.php?d=198622
More from Moodle
View All →CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows...
Medium
4.2
CVE-2025-34032
Moodle LMS Jmol Plugin Cross-site Scripting (XSS)
Medium
5.1
CVE-2025-34031
Moodle LMS Jmol Plugin Path Traversal
High
8.7
CVE-2024-38277
moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
Unknown
0
CVE-2024-38276
moodle: CSRF risks due to misuse of confirm_sesskey
Unknown
0
Affected Vendor
Moodle
View all reports →Affected Software
Moodle
Vulnerable Versions:
2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+
Timeline
Official Publish:
November 14th, 2019
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.