MGASA-2013-0280

Source
https://advisories.mageia.org/MGASA-2013-0280.html
Import Source
https://advisories.mageia.org/MGASA-2013-0280.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0280
Upstream
  • CVE-2013-4313
  • CVE-2013-4341
Published
2013-09-19T09:33:27Z
Modified
2026-04-16T06:24:10Z
Summary
Updated moodle package fixes multiple security vulnerabilities
Details

Updated moodle package fixes security vulnerabilities:

Null characters were allowed in query strings in Moodle before 2.4.6, which caused sql statements to terminate and fail, potentially allowing sql injection in Moodle's SQL Server driver (CVE-2013-4313).

Links to external blogs were not being adequately cleaned in Moodle before 2.4.6, potentially allowing for XSS attacks (CVE-2013-4341).

References
Credits

Affected packages

Mageia:3 / moodle

Package

Name
moodle
Purl
pkg:rpm/mageia/moodle?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.6-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0280.json"