CVE-2013-2081
CVE-2013-2081
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37822http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106965.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/106988.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/107026.htmlhttp://openwall.com/lists/oss-security/2013/05/21/1https://moodle.org/mod/forum/discuss.php?d=228933