1
Candidate: CVE-2013-1830
2
CRD: 2013-03-11 04:00:00 UTC
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1830
7
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before
8
2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles
9
setting, which allows remote attackers to obtain sensitive course-profile
10
information by leveraging the guest role, as demonstrated by a Google
17
Discovered-by: Helen Foster
21
upstream: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-37481
22
upstream_moodle: released (2.4.2, 2.3.5, 2.2.8)
23
hardy_moodle: ignored (reached end-of-life)
24
lucid_moodle: ignored (reached end-of-life)
25
oneiric_moodle: ignored (reached end-of-life)
26
precise_moodle: ignored (reached end-of-life)
27
precise/esm_moodle: DNE (precise was needed)
28
quantal_moodle: ignored (reached end-of-life)
29
raring_moodle: ignored (reached end-of-life)
30
saucy_moodle: ignored (reached end-of-life)
32
utopic_moodle: ignored (reached end-of-life)
33
vivid_moodle: ignored (reached end-of-life)
34
vivid/stable-phone-overlay_moodle: DNE
35
vivid/ubuntu-core_moodle: DNE
36
wily_moodle: ignored (reached end-of-life)
38
yakkety_moodle: ignored (reached end-of-life)
39
zesty_moodle: ignored (reached end-of-life)