CVE-2012-4401: Moodle

Medium severity, CVSS 4.0. EPSS: 1.1% chance of exploitation in the next 30 days.

Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.

Affected products

  • Moodle Moodle: version 2.2.0 only; version 2.2.1 only; version 2.2.2 only; version 2.2.3 only; version 2.2.4 only; version 2.3.0 only; …

Published 2012-09-19. Last modified 2026-06-16.