Information disclosure in Moodle - CVE-2013-2243

 

Information disclosure in Moodle - CVE-2013-2243

Published: July 29, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42702
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2243
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2013-2243

Install update from vendor's website.

moodle - update to 2.3.8-1.el6

External References

Related Security Bulletins