{"id":"MGASA-2013-0217","summary":"Updated moodle package fixes multiple security vulnerabilities","details":"Flash files distributed with the YUI library in Moodle before 2.4.5 may have\nallowed for cross-site scripting attacks (MSA-13-0025).\n\nPrivacy settings for the IMS-LTI (External tool) module in Moodle before\n2.4.5 were not able to be changed so personal information was always\ntransferred (MSA-13-0026).\n\nUsers were able to access a daemon-mode Chat activity in Moodle before 2.4.5\nwithout the required capability (CVE-2013-2242).\n\nIt was possible to determine answers from ID values in Lesson activity\nmatching questions in Moodle before 2.4.5 (CVE-2013-2243).\n\nConditional access rule values for user fields were able to contain unescaped\nHTML/JS that would be output to users in Moodle before 2.4.5 (CVE-2013-2244).\n\nWhen impersonating another user using RSS tokens in Moodle before 2.4.5, an\nerror was displayed, but block information relevant to the person being\nimpersonated was shown (CVE-2013-2245).\n\nThe Feedback module in Moodle before 2.4.5 was showing personal information \nto users without the needed capability (CVE-2013-2246).\n","modified":"2026-04-16T04:41:18.867058487Z","published":"2013-07-21T08:38:57Z","upstream":["CVE-2013-2242","CVE-2013-2243","CVE-2013-2244","CVE-2013-2245","CVE-2013-2246"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0217.html"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232496"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232497"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232498"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232500"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232501"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232502"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232503"},{"type":"WEB","url":"http://docs.moodle.org/dev/Moodle_2.4.5_release_notes"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=232108"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=10755"}],"affected":[{"package":{"name":"moodle","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/moodle?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.5-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0217.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}