Privilege Escalation in Moodle WebDAV Repositories

Privilege Escalation in Moodle WebDAV Repositories

CVE-2013-1836 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories, which allows remote authenticated users to read, modify, or delete arbitrary site-wide repositories by leveraging certain read access.

Learn more about our Web App Pen Testing.