CVE-2013-4938
Publication date 29 July 2013
Last updated 24 July 2024
Ubuntu priority
The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sendemailaddr, and acceptgrades settings, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an environment in which there was an ineffective attempt to enable the more secure values.
Status
Package | Ubuntu Release | Status |
---|---|---|
moodle | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |