Information disclosure in Moodle - CVE-2013-1835

 

Information disclosure in Moodle - CVE-2013-1835

Published: March 25, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42956
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1835
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2013-1835

Install update from vendor's website.

moodle - update to 2.2.9-1.el6

External References

Related Security Bulletins