MEDIUM
notes/edit.php in Moodle 1.9.x through 1.9.19, 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated users to reassign notes via a modified (1) userid or (2) courseid field
Published Mar 25, 2013
4.0
MEDIUMCVSS 2.0
EPSS 1.71%
Description
notes/edit.php in Moodle 1.9.x through 1.9.19, 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated users to reassign notes via a modified (1) userid or (2) courseid field.
Affected products
No data.
Configuration 1
OR
- 1.9.1
- 1.9.2
- 1.9.3
- 1.9.4
- 1.9.5
- 1.9.6
- 1.9.7
- 1.9.8
- 1.9.9
- 1.9.10
- 1.9.11
- 1.9.12
- 1.9.13
- 1.9.14
- 1.9.15
- 1.9.16
- 1.9.17
- 1.9.18
- 1.9.19
Configuration 2
OR
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.1.0
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.1.10
Configuration 3
Configuration 4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37411 x_refsource_CONFIRMPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.html vendor-advisoryx_refsource_FEDORA
- http://openwall.com/lists/oss-security/2013/03/25/2 mailing-listx_refsource_MLIST
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4822 Advisory
- https://github.com/advisories/GHSA-prrh-679x-79qh Advisory
- https://github.com/moodle/moodle/commit/1b628c489def6e7394821f53a838591aa392e332
- https://github.com/moodle/moodle/commit/646059869e36ea1db844ee0884fb50020348dab1
- https://github.com/moodle/moodle/commit/6a9235c998dab2ec0ddc49898a59dd5089156cb0
- https://github.com/moodle/moodle/commit/a28da5d9b8221e53d3a0815fd0a1dc27bd48816b
- https://github.com/moodle/moodle/commit/bc144ebbe0a78a1ac854454246f26472ba0748b7
- https://github.com/moodle/moodle/commit/e13f286026056febba20e931d71134a2d145a091
- https://github.com/moodle/moodle/commit/ebfdc35f2a33f14051e22af5410485fe6f1afc92
- https://moodle.org/mod/forum/discuss.php?d=225346 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-1834
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 25, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-1834
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4822 GHSA-PRRH-679X-79QH Assigner redhat
Published Mar 25, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2022-4822