{"id":"CVE-2013-4522","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-4522","summary":"lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send \"Cache-Control: private\" HTTP headers, which allows remote attackers…","details":"lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send \"Cache-Control: private\" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.","published":"2013-11-26T05:25:38.570","modified":"2026-06-16T23:57:23.080","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-38743"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2013/11/25/1"},{"type":"ADVISORY","url":"https://moodle.org/mod/forum/discuss.php?d=244479"},{"type":"EXPLOIT","url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-38743"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2013/11/25/1"},{"type":"ADVISORY","url":"https://moodle.org/mod/forum/discuss.php?d=244479"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:57:23.080"}}