rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which allows remote authenticated users to obtain sensitive block information by reading an RSS feed.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Information
Published : 2013-07-29 06:59
Updated : 2020-12-01 06:52
NVD link : CVE-2013-2245
Mitre link : CVE-2013-2245
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
moodle
- moodle