First published: Sat May 25 2013(Updated: )
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=2.4.0<2.4.4 | 2.4.4 |
composer/moodle/moodle | >=2.3.0<2.3.7 | 2.3.7 |
composer/moodle/moodle | <2.2.10 | 2.2.10 |
Moodle | =2.1.0 | |
Moodle | =2.1.1 | |
Moodle | =2.1.2 | |
Moodle | =2.1.3 | |
Moodle | =2.1.4 | |
Moodle | =2.1.5 | |
Moodle | =2.1.6 | |
Moodle | =2.1.7 | |
Moodle | =2.1.8 | |
Moodle | =2.1.9 | |
Moodle | =2.1.10 | |
Moodle | =2.2.0 | |
Moodle | =2.2.1 | |
Moodle | =2.2.2 | |
Moodle | =2.2.3 | |
Moodle | =2.2.4 | |
Moodle | =2.2.5 | |
Moodle | =2.2.6 | |
Moodle | =2.2.7 | |
Moodle | =2.2.8 | |
Moodle | =2.2.9 | |
Moodle | =2.3.0 | |
Moodle | =2.3.1 | |
Moodle | =2.3.2 | |
Moodle | =2.3.3 | |
Moodle | =2.3.4 | |
Moodle | =2.3.5 | |
Moodle | =2.3.6 | |
Moodle | =2.4.0 | |
Moodle | =2.4.1 | |
Moodle | =2.4.2 | |
Moodle | =2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2081 is classified as a medium severity vulnerability due to the potential exposure of sensitive site information.
To fix CVE-2013-2081, you should upgrade to Moodle version 2.4.4 or later, 2.3.7 or later, or 2.2.10 or later.
CVE-2013-2081 affects Moodle versions 2.1.0 through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4.
CVE-2013-2081 is a vulnerability that allows remote hubs to access sensitive site information.
Yes, if you are using any of the affected Moodle versions, your site could be compromised by CVE-2013-2081.