PT-2016-1305 · Moodle · Moodle

Daniel Palou

·

Publicado

2015-12-05

·

Atualizado

2022-05-13

·

CVE-2015-5339

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 2.6.11 and earlier Moodle versions 2.7.x before 2.7.11 Moodle versions 2.8.x before 2.8.9 Moodle versions 2.9.x before 2.9.3
Description The issue is related to the core enrol get enrolled users web service in Moodle, which does not properly implement group-based access restrictions. This allows remote authenticated users to obtain sensitive course-participant information via a web-service request.
Recommendations For versions 2.6.11 and earlier, update to a version later than 2.6.11. For versions 2.7.x before 2.7.11, update to version 2.7.11 or later. For versions 2.8.x before 2.8.9, update to version 2.8.9 or later. For versions 2.9.x before 2.9.3, update to version 2.9.3 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00602
CVE-2015-5339
GHSA-GMHR-6F43-7QPJ
MGASA-2015-0464

Produtos afetados

Moodle