CVE-2015-3180: Infoleak
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by leveraging access to a student account with a suspended enrolment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3180?
CVE-2015-3180 has been assigned a medium severity level due to the potential for unauthorized access to sensitive course-structure information.
How do I fix CVE-2015-3180?
To fix CVE-2015-3180, upgrade your Moodle installation to version 2.6.11, 2.7.8, or 2.8.6 or later.
Who is affected by CVE-2015-3180?
CVE-2015-3180 affects Moodle versions 2.5.9 and earlier, as well as certain versions of 2.6.x, 2.7.x, and 2.8.x prior to their respective patched versions.
What causes CVE-2015-3180?
CVE-2015-3180 is caused by improper handling of access control in navigationlib.php, allowing unauthorized users to view sensitive information.
Can CVE-2015-3180 be exploited remotely?
Yes, CVE-2015-3180 can be exploited remotely by authenticated users with access to suspended student accounts.