CVE-2012-5471: Moodle
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.
Affected products
- Moodle Moodle: version 2.1.0 only; version 2.1.1 only; version 2.1.2 only; version 2.1.3 only; version 2.1.4 only; version 2.1.5 only; …
Published 2012-11-21. Last modified 2026-06-16.