The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-07-20 03:40
Updated : 2023-02-12 19:23
NVD link : CVE-2011-4588
Mitre link : CVE-2011-4588
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
moodle
- moodle