CVE-2012-6102: Moodle

Medium severity, CVSS 6.4. EPSS: 1.4% chance of exploitation in the next 30 days.

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.

Affected products

  • Moodle Moodle: version 2.3.0 only; version 2.3.1 only; version 2.3.2 only; version 2.3.3 only; version 2.4.0 only

Published 2013-01-27. Last modified 2026-06-16.