Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-2082

Опубликовано: 25 мая 2013
Источник: debian
EPSS Низкий

Описание

Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comments, which allows remote attackers to obtain sensitive information via a crafted request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodlefixed2.5-1package
moodleno-dsasqueezepackage

Примечания

  • http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37245

EPSS

Процентиль: 68%
0.006
Низкий

Связанные уязвимости

ubuntu
около 12 лет назад

Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comments, which allows remote attackers to obtain sensitive information via a crafted request.

nvd
около 12 лет назад

Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comments, which allows remote attackers to obtain sensitive information via a crafted request.

github
около 3 лет назад

Moodle does not enforce capability requirements for reading blog comments

EPSS

Процентиль: 68%
0.006
Низкий