PT-2013-3421 · Moodle · Moodle

Frédéric Massart

·

Published

2013-03-11

·

Updated

2022-05-13

·

CVE-2013-1836

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moodle versions 2.0 through 2.1.10 Moodle versions 2.2.x through 2.2.7 Moodle versions 2.3.x through 2.3.4 Moodle versions 2.4.x through 2.4.1
Description The issue concerns improper privilege management for WebDAV repositories. This allows remote authenticated users to read, modify, or delete arbitrary site-wide repositories by leveraging certain read access.
Recommendations For versions 2.0 through 2.1.10, update to version 2.1.11 or later. For versions 2.2.x through 2.2.7, update to version 2.2.8 or later. For versions 2.3.x through 2.3.4, update to version 2.3.5 or later. For versions 2.4.x through 2.4.1, update to version 2.4.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1836
GHSA-664Q-MRXX-2X2V

Affected Products

Moodle