CVE-2013-2242: Medium severity moodle vulnerability
mod/chat/guisockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authenticated users to bypass intended access restrictions via an HTTP session to a chat server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2242?
CVE-2013-2242 is classified as a moderate severity vulnerability that allows remote authenticated users to bypass access restrictions.
How can I fix CVE-2013-2242?
To remediate CVE-2013-2242, you should upgrade Moodle to the latest version that addresses this vulnerability.
Which versions of Moodle are affected by CVE-2013-2242?
CVE-2013-2242 affects Moodle versions 2.1.0 through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1.
What type of access does CVE-2013-2242 allow unauthorized users?
CVE-2013-2242 allows remote authenticated users to gain access to the daemon-mode chat feature without proper authorization.
Is there a patch available for CVE-2013-2242?
Yes, patches are included in the versions of Moodle that address CVE-2013-2242, and upgrading is necessary to apply these fixes.