CVE-2013-2082

Moodle < 2.2.10 - Unauthenticated Sensitive Information Exposure via Blog Comments

Title source: llm
STIX 2.1

Description

Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comments, which allows remote attackers to obtain sensitive information via a crafted request.

References (6)

Core 6
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106965.html
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2013/05/21/1
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/107026.html
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=228934
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106988.html

Scores

EPSS 0.0060
EPSS Percentile 69.7%

Details

CWE
CWE-264
Status published
Products (33)
moodle/moodle 2.1.0
moodle/moodle 2.1.1
moodle/moodle 2.1.2
moodle/moodle 2.1.3
moodle/moodle 2.1.4
moodle/moodle 2.1.5
moodle/moodle 2.1.6
moodle/moodle 2.1.7
moodle/moodle 2.1.8
moodle/moodle 2.1.9
... and 23 more
Published May 25, 2013
Tracked Since Feb 18, 2026