Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2245
HistoryJul 29, 2013 - 12:00 a.m.

CVE-2013-2245

2013-07-2900:00:00
ubuntu.com
ubuntu.com
14

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.001

Percentile

41.9%

rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before
2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly
implement the use of RSS tokens for impersonation, which allows remote
authenticated users to obtain sensitive block information by reading an RSS
feed.

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.001

Percentile

41.9%