CVE-2015-3176: Infoleak
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name information by attempting to self-register.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3176?
CVE-2015-3176 has a medium severity rating due to its potential exploitation by remote attackers to access sensitive information.
How do I fix CVE-2015-3176?
To remediate CVE-2015-3176, upgrade your Moodle installation to versions 2.6.11, 2.7.8, or 2.8.6 or later.
What versions of Moodle are affected by CVE-2015-3176?
CVEs-2015-3176 affects Moodle versions up to 2.5.9 and earlier releases of 2.6.x, 2.7.x, and 2.8.x.
Can CVE-2015-3176 be exploited without authentication?
Yes, CVE-2015-3176 can be exploited without authentication, allowing attackers to obtain sensitive user information.
What type of information can be exposed due to CVE-2015-3176?
CVE-2015-3176 can expose sensitive full-name information of users during the self-registration process.