CVE-2015-2266: Infoleak
message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2266?
CVE-2015-2266 has a severity of medium as it allows unauthorized access to sensitive personal messages.
How do I fix CVE-2015-2266?
To fix CVE-2015-2266, upgrade to Moodle version 2.8.4, 2.7.6, or 2.6.9.
What versions of Moodle are affected by CVE-2015-2266?
CVE-2015-2266 affects Moodle versions 2.5.0 to 2.5.9, 2.6.0 to 2.6.8, 2.7.0 to 2.7.5, and 2.8.0 to 2.8.3.
What type of vulnerability is CVE-2015-2266?
CVE-2015-2266 is a privilege escalation vulnerability that allows authenticated users to access arbitrary conversations.
Is CVE-2015-2266 exploitable remotely?
Yes, CVE-2015-2266 is exploitable by remote authenticated users, which poses a risk to the accessibility of sensitive information.