CVE-2013-1832: Infoleak
repository/webdav/lib.php in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 includes the WebDAV password in the configuration form, which allows remote authenticated administrators to obtain sensitive information by configuring an instance.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1832?
CVE-2013-1832 has a medium severity level due to its potential to expose sensitive information.
How do I fix CVE-2013-1832?
To fix CVE-2013-1832, upgrade to Moodle versions 2.4.2 or later, 2.3.5 or later, or 2.2.8 or later.
Which versions of Moodle are affected by CVE-2013-1832?
Moodle versions 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 are affected by CVE-2013-1832.
What is the nature of the vulnerability in CVE-2013-1832?
The vulnerability in CVE-2013-1832 allows remote authenticated administrators to obtain sensitive information by configuring an instance.
Can I mitigate CVE-2013-1832 without upgrading?
Mitigation of CVE-2013-1832 without upgrading is not recommended, as the best resolution is to update to a secure version.