CVE-2013-2081: Moodle
Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider "don't send" attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Affected products
- Moodle Moodle: version 2.1.0 only; version 2.1.1 only; version 2.1.2 only; version 2.1.3 only; version 2.1.4 only; version 2.1.5 only; …
Published 2013-05-25. Last modified 2026-06-16.