{"id":"GHSA-xr24-jp5c-6c4v","summary":"Moodle reveals absolute path in exception message","details":"lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the absolute path in an exception message.","aliases":["CVE-2013-1831"],"modified":"2024-12-05T05:38:39.182548Z","published":"2022-05-13T01:12:57Z","database_specific":{"nvd_published_at":"2013-03-25T21:55:00Z","cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-22T15:58:11Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1831"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/2c7cdbb3b0b6ba4dd64297463d37a5acbd730216"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/53c66110a878f4f4644728138ea97c22990263e3"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/8d220cb552d9c55b98aef70e2f40ef560efeb79b"},{"type":"WEB","url":"https://github.com/moodle/moodle/commit/b3daaada49a2dd83a4f1e832465d5c318f9f275c"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=225342"},{"type":"WEB","url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-36901"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.html"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2013/03/25/2"}],"affected":[{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.1.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xr24-jp5c-6c4v/GHSA-xr24-jp5c-6c4v.json"}},{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xr24-jp5c-6c4v/GHSA-xr24-jp5c-6c4v.json"}},{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.3.0"},{"fixed":"2.3.5"}]}],"versions":["v2.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xr24-jp5c-6c4v/GHSA-xr24-jp5c-6c4v.json"}},{"package":{"name":"moodle/moodle","ecosystem":"Packagist","purl":"pkg:composer/moodle/moodle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.4.2"}]}],"versions":["v2.4.0","v2.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xr24-jp5c-6c4v/GHSA-xr24-jp5c-6c4v.json"}}],"schema_version":"1.9.0"}