CVE-2015-0211: Infoleak
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0211?
CVE-2015-0211 has a high severity rating due to its potential for unauthorized access to course management features in Moodle.
How do I fix CVE-2015-0211?
To fix CVE-2015-0211, update your Moodle installation to versions 2.5.10, 2.6.7, 2.7.4, or 2.8.2 or later.
Which versions of Moodle are affected by CVE-2015-0211?
CVE-2015-0211 affects Moodle versions up to 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2.
What capabilities are not considered due to CVE-2015-0211?
CVE-2015-0211 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities.
Can remote authenticated users exploit CVE-2015-0211?
Yes, remote authenticated users can exploit CVE-2015-0211 to obtain sensitive information related to registered-tool list searches.