CVE-2013-2243: Infoleak
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2243?
CVE-2013-2243 has a medium severity rating due to the potential exposure of sensitive answer information.
How do I fix CVE-2013-2243?
To fix CVE-2013-2243, upgrade Moodle to version 2.3.8, 2.4.5, or 2.5.1 or later.
Who is affected by CVE-2013-2243?
CVE-2013-2243 affects remote authenticated users of Moodle versions up to 2.2.11, and 2.3.x through 2.3.7, 2.4.x through 2.4.4, and 2.5.x through 2.5.0.
What is the impact of CVE-2013-2243?
The impact of CVE-2013-2243 is that it allows remote authenticated users to access sensitive information by viewing the HTML source code.
Is CVE-2013-2243 still a risk if Moodle is updated?
CVE-2013-2243 is no longer a risk if the Moodle installation is updated to a patched version.