CVE-2013-2079: Medium severity moodle vulnerability
mod/assign/locallib.php in the assignment module in Moodle 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download (aka downloadall) requests, which allows remote authenticated users to read other users' assignments by leveraging the student role.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2079?
CVE-2013-2079 is classified as a high severity vulnerability due to its potential to allow unauthorized access to other users' assignment submissions.
How do I fix CVE-2013-2079?
To fix CVE-2013-2079, upgrade to Moodle versions 2.3.7 or 2.4.4 or later where the vulnerability has been addressed.
Who is affected by CVE-2013-2079?
Users of Moodle versions 2.3.0 through 2.3.6 and 2.4.0 through 2.4.3 are affected by CVE-2013-2079.
What type of attack does CVE-2013-2079 facilitate?
CVE-2013-2079 facilitates unauthorized access, allowing remote authenticated users to read other users' assignment submissions.
What component of Moodle is impacted by CVE-2013-2079?
CVE-2013-2079 impacts the assignment module, specifically the handling of ZIP assignment-archive download requests.