Information disclosure in Moodle - CVE-2013-1832

 

Information disclosure in Moodle - CVE-2013-1832

Published: March 25, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42953
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1832
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

repository/webdav/lib.php in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 includes the WebDAV password in the configuration form, which allows remote authenticated administrators to obtain sensitive information by configuring an instance.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2013-1832

Install update from vendor's website.

moodle - update to 2.2.9-1.el6

External References

Related Security Bulletins