CVE-2015-5338: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1) mod/lesson/mediafile.php or (2) mod/lesson/view.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5338?
CVE-2015-5338 has a medium severity level due to its potential for cross-site request forgery attacks.
How do I fix CVE-2015-5338?
To remediate CVE-2015-5338, update Moodle to version 2.7.11, 2.8.9, or 2.9.3 or later.
What versions of Moodle are affected by CVE-2015-5338?
CVE-2015-5338 affects Moodle versions prior to 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3.
What type of vulnerability is CVE-2015-5338?
CVE-2015-5338 is classified as a cross-site request forgery (CSRF) vulnerability.
Can CVE-2015-5338 be exploited remotely?
Yes, CVE-2015-5338 allows remote attackers to hijack the authentication of users, making it a significant risk.