PT-2013-5058 · Moodle · Moodle

Tony Levi

·

Publicado

2013-11-26

·

Atualizado

2022-05-13

·

CVE-2013-4522

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Moodle versions 2.2.11 and earlier, 2.3.x before 2.3.10, 2.4.x before 2.4.7, 2.5.x before 2.5.3
Description The issue allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server, due to the lack of "Cache-Control: private" HTTP headers.
Recommendations For versions 2.2.11 and earlier, update to version 2.2.12 or later. For versions 2.3.x before 2.3.10, update to version 2.3.10 or later. For versions 2.4.x before 2.4.7, update to version 2.4.7 or later. For versions 2.5.x before 2.5.3, update to version 2.5.3 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4522
GHSA-VM9C-39JX-Q45W
MGASA-2013-0356

Produtos afetados

Moodle