CVE-2013-2245: Medium severity moodle vulnerability
rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2245?
CVE-2013-2245 has a medium severity rating, indicating potential risk to sensitive information.
How do I fix CVE-2013-2245?
To fix CVE-2013-2245, upgrade to Moodle version 2.2.11, 2.3.8, 2.4.5, or 2.5.1 or newer.
What kind of information can be accessed due to CVE-2013-2245?
CVE-2013-2245 allows unauthorized access to sensitive block information through RSS feeds.
Which versions of Moodle are affected by CVE-2013-2245?
Moodle versions up to 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 are affected.
Who is primarily at risk from CVE-2013-2245?
Remote authenticated users are primarily at risk from CVE-2013-2245 due to the improper implementation of RSS tokens.