CVE-2011-4203
Last modified
CVE-2011-4203 is a vulnerability of currently unknown severity. CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving the url variable.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving the url variable.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | 1.9.1 |
| Moodle | Moodle | 1.9.2 |
| Moodle | Moodle | 1.9.3 |
| Moodle | Moodle | 1.9.4 |
| Moodle | Moodle | 1.9.5 |
| Moodle | Moodle | 1.9.6 |
| Moodle | Moodle | 1.9.7 |
| Moodle | Moodle | 1.9.8 |
| Moodle | Moodle | 1.9.9 |
| Moodle | Moodle | 1.9.10 |
| Moodle | Moodle | 1.9.11 |
| Moodle | Moodle | 1.9.12 |
| Moodle | Moodle | 1.9.13 |
| Moodle | Moodle | 1.9.14 |
| Moodle | Moodle | 2.0.0 |
| Moodle | Moodle | 2.0.1 |
| Moodle | Moodle | 2.0.2 |
| Moodle | Moodle | 2.0.3 |
| Moodle | Moodle | 2.0.4 |
| Moodle | Moodle | 2.0.5 |
| Moodle | Moodle | 2.1.0 |
| Moodle | Moodle | 2.1.1 |
| Moodle | Moodle | 2.1.2 |
| Moodle | Moodle | 2.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-4203?
How severe is CVE-2011-4203?
How do I fix CVE-2011-4203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-4193Cross-site scripting (XSS) vulnerability in the overlay file…
- CVE-2011-4194Buffer overflow in Novell iPrint Server in Novell Open Enter…
- CVE-2011-4195kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 befor…
- CVE-2011-4197etc/inc/certs.inc in the PKI implementation in pfSense befor…
- CVE-2011-4201remote_support.cgi in the Tadasoft Restorepoint 3.2 evaluati…
- CVE-2011-4202The Tadasoft Restorepoint 3.2 evaluation image uses weak per…
- CVE-2011-4211The FakeFile implementation in the sandbox environment in th…
- CVE-2011-4212The sandbox environment in the Google App Engine Python SDK …
- CVE-2011-4213The sandbox environment in the Google App Engine Python SDK …
- CVE-2011-4214OneOrZero Action & Information Management System (AIMS) 2.7.…
- CVE-2011-4215SQL injection vulnerability in lib/ooz_access.php in OneOrZe…
- CVE-2011-4216Investintech.com SlimPDF Reader does not properly restrict w…
Are you affected by CVE-2011-4203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
