First published: Sat May 25 2013(Updated: )
mod/assign/locallib.php in the assignment module in Moodle 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download (aka downloadall) requests, which allows remote authenticated users to read other users' assignments by leveraging the student role.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =2.3.0 | |
Moodle | =2.3.1 | |
Moodle | =2.3.2 | |
Moodle | =2.3.3 | |
Moodle | =2.3.4 | |
Moodle | =2.3.5 | |
Moodle | =2.3.6 | |
Moodle | =2.4.0 | |
Moodle | =2.4.1 | |
Moodle | =2.4.2 | |
Moodle | =2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2079 is classified as a high severity vulnerability due to its potential to allow unauthorized access to other users' assignment submissions.
To fix CVE-2013-2079, upgrade to Moodle versions 2.3.7 or 2.4.4 or later where the vulnerability has been addressed.
Users of Moodle versions 2.3.0 through 2.3.6 and 2.4.0 through 2.4.3 are affected by CVE-2013-2079.
CVE-2013-2079 facilitates unauthorized access, allowing remote authenticated users to read other users' assignment submissions.
CVE-2013-2079 impacts the assignment module, specifically the handling of ZIP assignment-archive download requests.