CVE-2015-2271: Medium severity moodle vulnerability
tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2271?
CVE-2015-2271 has a medium severity level as it allows authenticated users to bypass access restrictions.
How do I fix CVE-2015-2271?
To fix CVE-2015-2271, upgrade Moodle to version 2.8.4, 2.7.6, or 2.6.9 or later.
What versions are affected by CVE-2015-2271?
CVE-2015-2271 affects Moodle versions 2.5.9 and earlier, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4.
What capability is not considered in CVE-2015-2271?
CVE-2015-2271 does not consider the moodle/tag:flag capability before flagging inappropriate actions.
Who is impacted by the vulnerability CVE-2015-2271?
Remote authenticated users of Moodle can exploit CVE-2015-2271 to bypass intended access restrictions.