CVE-2013-1832

medium

Description

repository/webdav/lib.php in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 includes the WebDAV password in the configuration form, which allows remote authenticated administrators to obtain sensitive information by configuring an instance.

References

https://moodle.org/mod/forum/discuss.php?d=225343

http://openwall.com/lists/oss-security/2013/03/25/2

http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.html

http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.html

http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37681

Details

Source: Mitre, NVD

Published: 2013-03-25

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Severity: Medium