CVE-2013-2080: Infoleak
The coregrade component in Moodle through 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly consider the existence of hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role and reading the Gradebook Overview report.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2080?
The severity of CVE-2013-2080 is classified as medium due to the potential exposure of sensitive information.
How do I fix CVE-2013-2080?
To fix CVE-2013-2080, upgrade Moodle to version 2.3.7 or higher, or version 2.4.4 or higher.
Who is affected by CVE-2013-2080?
CVE-2013-2080 affects Moodle versions 2.2.0 through 2.2.10, 2.3.0 through 2.3.6, and 2.4.0 through 2.4.3.
What type of vulnerability is CVE-2013-2080?
CVE-2013-2080 is an information disclosure vulnerability that allows unauthorized access to hidden grades.
What are the potential impacts of CVE-2013-2080?
The potential impacts of CVE-2013-2080 include the exposure of sensitive student grade information to unauthorized users.