CVE-2013-2081: Medium severity moodle vulnerability
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2081?
CVE-2013-2081 is classified as a medium severity vulnerability due to the potential exposure of sensitive site information.
How do I fix CVE-2013-2081?
To fix CVE-2013-2081, you should upgrade to Moodle version 2.4.4 or later, 2.3.7 or later, or 2.2.10 or later.
What systems are affected by CVE-2013-2081?
CVE-2013-2081 affects Moodle versions 2.1.0 through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4.
Is CVE-2013-2081 an exploit or a vulnerability?
CVE-2013-2081 is a vulnerability that allows remote hubs to access sensitive site information.
Can CVE-2013-2081 affect my Moodle site?
Yes, if you are using any of the affected Moodle versions, your site could be compromised by CVE-2013-2081.