CVE-2013-1830
published 2013-03-25CVE-2013-1830: user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting…
PriorityP420medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.58%
72.7th percentile
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.
Affected
107 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
| moodle | moodle | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moodle does not enforce the forceloginforprofiles setting
osv·2022-05-13
CVE-2013-1830 [MEDIUM] Moodle does not enforce the forceloginforprofiles setting
Moodle does not enforce the forceloginforprofiles setting
`user/view.php` in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the `forceloginforprofiles` setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.
GHSA
Moodle does not enforce the forceloginforprofiles setting
ghsa·2022-05-13
CVE-2013-1830 [MEDIUM] CWE-284 Moodle does not enforce the forceloginforprofiles setting
Moodle does not enforce the forceloginforprofiles setting
`user/view.php` in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the `forceloginforprofiles` setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.
OSV
CVE-2013-1830: user/view
osv·2013-03-11·CVSS 5.0
CVE-2013-1830 [MEDIUM] CVE-2013-1830: user/view
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1830 moodle: Information leak in course profiles (MSA-13-0012)
bugzilla·2013-03-25·CVSS 5.0
CVE-2013-1830 [MEDIUM] CVE-2013-1830 moodle: Information leak in course profiles (MSA-13-0012)
CVE-2013-1830 moodle: Information leak in course profiles (MSA-13-0012)
An information disclosure flaw was found in the way Moodle, a course management system, honoured 'forceloginforprofiles' configuration option / settings (course profile information was available regardless of this option being enabled / applied). Remote attacker (logged in as Moodle guest) could use this flaw to obtain sensitive information.
References:
[1] http://www.openwall.com/lists/oss-security/2013/03/25/2
Relevant upstream patch:
[2] http://git.moodle.org/gw?p=moodle.git;a=commit;h=3ecc63e9dbe29c6a5a8f65fa8e7980ba0fffb5a8
Discussion:
This issue affects the versions of the moodle package, as shipped with Fedora release of 18, 17, and Fedora EPEL-6. Please schedule an update.
--
This issue (probably [*]) do
Bugzilla
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-17]
bugzilla·2013-03-25·CVSS 9.1
CVE-2013-1830 [CRITICAL] CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-17]
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-18]
bugzilla·2013-03-25·CVSS 9.1
CVE-2013-1830 [CRITICAL] CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-18]
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and
Bugzilla
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [epel-6]
bugzilla·2013-03-25·CVSS 9.1
CVE-2013-1830 [CRITICAL] CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [epel-6]
CVE-2013-1830 CVE-2013-1831 CVE-2013-1832 CVE-2013-1833 CVE-2012-3363 CVE-2013-1834 CVE-2013-1835 CVE-2013-1836 moodle various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37481http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.htmlhttp://openwall.com/lists/oss-security/2013/03/25/2https://moodle.org/mod/forum/discuss.php?d=225341http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37481http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.htmlhttp://openwall.com/lists/oss-security/2013/03/25/2https://moodle.org/mod/forum/discuss.php?d=225341
2013-03-25
Published