Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated May 8, 2025
Package
Affected versions
< 2.3.10
>= 2.4.0-beta, < 2.4.7
>= 2.5.0-beta, < 2.5.3
Patched versions
2.3.10
2.4.7
2.5.3
Description
Published by the National Vulnerability Database
Nov 26, 2013
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
May 8, 2025
Last updated
May 8, 2025
lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.
References