Vulnerability Details CVE-2011-4592
The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.7%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2011-4592
-
cpe:2.3:a:moodle:moodle:2.0.0
-
cpe:2.3:a:moodle:moodle:2.0.1
-
cpe:2.3:a:moodle:moodle:2.0.2
-
cpe:2.3:a:moodle:moodle:2.0.3
-
cpe:2.3:a:moodle:moodle:2.0.4
-
cpe:2.3:a:moodle:moodle:2.0.5
-
cpe:2.3:a:moodle:moodle:2.1.0
-
cpe:2.3:a:moodle:moodle:2.1.1
-
cpe:2.3:a:moodle:moodle:2.1.2