CVE-2015-3179: Low severity moodle vulnerability
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3179?
CVE-2015-3179 is classified as a medium severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2015-3179?
To fix CVE-2015-3179, upgrade Moodle to version 2.8.6, 2.7.8, or 2.6.11 or later.
What versions of Moodle are affected by CVE-2015-3179?
CVE-2015-3179 affects Moodle versions up to 2.5.9, all 2.6.x versions before 2.6.11, all 2.7.x versions before 2.7.8, and all 2.8.x versions before 2.8.6.
What type of attack does CVE-2015-3179 facilitate?
CVE-2015-3179 allows remote authenticated users to bypass intended login restrictions.
Is CVE-2015-3179 related to user account management in Moodle?
Yes, CVE-2015-3179 involves bypassing login restrictions related to unconfirmed suspended accounts in Moodle.