PT-2016-1289 · Moodle · Moodle
Juan Leyva
·
Published
2016-02-22
·
Updated
2020-12-01
·
CVE-2015-3273
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle versions 2.9.x through 2.9.0
Description
The issue is related to insufficient access control in the mod/forum/post.php function of the Moodle learning management system. This can be exploited by a remote attacker to bypass existing access restrictions by leveraging group authorization. The problem arises because the
mod/forum:canposttomygroups capability is not properly considered before authorizing certain actions, such as "Post a copy to all groups".Recommendations
For Moodle versions 2.9.x through 2.9.0, update to version 2.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
mod/forum/post.php function to minimize the risk of exploitation. Additionally, review and adjust group authorization settings to ensure that access restrictions are properly enforced.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moodle