CVE-2013-2083: Input Validation
The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly handle a certain array-element syntax, which allows remote attackers to bypass intended form-data filtering via a crafted request.
Other sources
The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly handle a certain array-element syntax, which allows remote attackers to bypass intended form-data filtering via a crafted request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2083?
CVE-2013-2083 is classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2013-2083?
To fix CVE-2013-2083, upgrade to Moodle versions 2.2.10, 2.3.7, or 2.4.4 or later.
Which versions of Moodle are affected by CVE-2013-2083?
CVE-2013-2083 affects Moodle versions 2.1.0 to 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4.
What kind of attack can CVE-2013-2083 facilitate?
CVE-2013-2083 can facilitate remote attacks that bypass intended form-data filtering through crafted requests.
Is there a workaround for CVE-2013-2083 if I cannot upgrade?
There is no documented workaround for CVE-2013-2083, so upgrading is the recommended mitigation.