4
CVSSv2

CVE-2013-2079

Published: 25/05/2013 Updated: 01/12/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

mod/assign/locallib.php in the assignment module in Moodle 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download (aka downloadall) requests, which allows remote authenticated users to read other users' assignments by leveraging the student role.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.3.4

moodle moodle 2.3.3

moodle moodle 2.3.2

moodle moodle 2.3.1

moodle moodle 2.3.0

moodle moodle 2.3.6

moodle moodle 2.3.5

moodle moodle 2.4.3

moodle moodle 2.4.0

moodle moodle 2.4.1

moodle moodle 2.4.2