MGASA-2013-0162

Source
https://advisories.mageia.org/MGASA-2013-0162.html
Import Source
https://advisories.mageia.org/MGASA-2013-0162.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0162
Upstream
  • CVE-2013-2079
  • CVE-2013-2080
  • CVE-2013-2081
  • CVE-2013-2082
  • CVE-2013-2083
Published
2013-06-06T12:24:33Z
Modified
2026-04-16T06:24:12Z
Summary
Updated moodle package fix security vulnerabilities
Details

The assignment module in Moodle before 2.4.4 was not checking capabilities for users downloading all assignments as a zip (CVE-2013-2079).

The Gradebook's Overview report in Moodle before 2.4.4 was showing grade totals that may have incorrectly included hidden grades (CVE-2013-2080).

When registering a site on a hub (not Moodle.net) site in Moodle before 2.4.4, information was being sent to the hub regardless of settings chosen (CVE-2013-2081).

There was no check of permissions for viewing comments on blog posts in Moodle before 2.4.4 (CVE-2013-2082).

Form elements named using a specific naming scheme were not being filtered correctly in Moodle before 2.4.4 (CVE-2013-2083).

References
Credits

Affected packages

Mageia:3 / moodle

Package

Name
moodle
Purl
pkg:rpm/mageia/moodle?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.4-1.1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0162.json"