CVE-2013-2081 Information

Description

Moodle through 2.1.10 2.2.x before 2.2.10 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider \don’t send\ attributes during hub registration which allows remote hubs to obtain sensitive site information by reading form data.

Reference

http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37822 http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106965.html http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106988.html http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107026.html http://openwall.com/lists/oss-security/2013/05/21/1 https://moodle.org/mod/forum/discuss.php?d=228933

Share on: