Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-1829

Опубликовано: 25 мар. 2013
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:moodle:moodle:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:2.4.1:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00199
Низкий

4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 12 лет назад

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.

debian
около 12 лет назад

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not ...

github
около 3 лет назад

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.

EPSS

Процентиль: 42%
0.00199
Низкий

4 Medium

CVSS2

Дефекты

CWE-200