Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-1835

Overview

Vulnerability Score 3.5 3.5
CVE Id CVE-2013-1835
Last Modified 05 Dec 2013 12:25:14
Published 25 Mar 2013 05:55:04
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication SINGLE_INSTANCE

CVE-2013-1835

Summary

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.

Vulnerable Systems

Application

  • Moodle 2.0

  • Moodle 2.0.1

  • Moodle 2.0.2

  • Moodle 2.0.3

  • Moodle 2.0.4

  • Moodle 2.0.5

  • Moodle 2.0.6

  • Moodle 2.0.7

  • Moodle 2.0.8

  • Moodle 2.0.9

  • Moodle 2.1

  • Moodle 2.1.1

  • Moodle 2.1.10

  • Moodle 2.1.2

  • Moodle 2.1.3

  • Moodle 2.1.4

  • Moodle 2.1.5

  • Moodle 2.1.6

  • Moodle 2.1.7

  • Moodle 2.1.8

  • Moodle 2.1.9

  • Moodle 2.2

  • Moodle 2.2.1

  • Moodle 2.2.2

  • Moodle 2.2.3

  • Moodle 2.2.4

  • Moodle 2.2.5

  • Moodle 2.2.6

  • Moodle 2.2.7

  • Moodle 2.3

  • Moodle 2.3.1

  • Moodle 2.3.2

  • Moodle 2.3.3

  • Moodle 2.3.4

  • Moodle 2.4

  • Moodle 2.4.1


References

CONFIRM - http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36426

CONFIRM - https://moodle.org/mod/forum/discuss.php?d=225347

MLIST - [oss-security] 20130325 Moodle security notifications public

FEDORA - FEDORA-2013-4387

FEDORA - FEDORA-2013-4404


Last Updated: 27 May 2016 11:02:08