CVE-2012-3398: Moodle

Medium severity, CVSS 4.0. EPSS: 1.3% chance of exploitation in the next 30 days.

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

Affected products

  • Moodle Moodle: version 1.9.1 only; version 1.9.2 only; version 1.9.3 only; version 1.9.4 only; version 1.9.5 only; version 1.9.6 only; …

Published 2012-07-23. Last modified 2026-06-16.