CVE-2015-5268: Infoleak
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5268?
CVE-2015-5268 is classified as a medium severity vulnerability due to its potential to expose sensitive information to remote authenticated users.
How do I fix CVE-2015-5268?
To fix CVE-2015-5268, upgrade your Moodle installation to version 2.7.10, 2.8.8, or 2.9.2 or later.
What versions of Moodle are affected by CVE-2015-5268?
CVE-2015-5268 affects Moodle versions up to and including 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2.
Can CVE-2015-5268 lead to unauthorized access to user ratings?
Yes, CVE-2015-5268 allows remote authenticated users to access and read group-based rating values they should not have permission to view.
What type of attack does CVE-2015-5268 facilitate?
CVE-2015-5268 can facilitate information disclosure attacks where unauthorized users gain access to sensitive rating information.