CVE-2015-5272: Medium severity moodle vulnerability
Published Feb 22, 2016
·Updated
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
Affected Software
10 affected components
Moodle moodle=2.7.0
Moodle moodle=2.7.1
Moodle moodle=2.7.2
Moodle moodle=2.7.3
Moodle moodle=2.7.4
Moodle moodle=2.7.5
Moodle moodle=2.7.6
Moodle moodle=2.7.7
Moodle moodle=2.7.8
Moodle moodle=2.7.9
Event History
Feb 22, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5272?
CVE-2015-5272 has a high severity rating due to the potential for remote authenticated users to post to arbitrary groups.
2
How do I fix CVE-2015-5272?
To fix CVE-2015-5272, update Moodle to version 2.7.10 or later to patch the vulnerability.
3
What versions of Moodle are affected by CVE-2015-5272?
CVE-2015-5272 affects Moodle versions 2.7.0 through 2.7.9.
4
Who can exploit CVE-2015-5272?
Remote authenticated users with the teacher role can exploit CVE-2015-5272 to post to arbitrary groups.
5
What type of vulnerability is CVE-2015-5272?
CVE-2015-5272 is a privilege escalation vulnerability related to the Forum module in Moodle.