CVE-2015-5339: Infoleak
The coreenrolgetenrolledusers web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain sensitive course-participant information via a web-service request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5339?
The severity of CVE-2015-5339 is classified as medium, as it allows authenticated users to gain access to sensitive information.
How do I fix CVE-2015-5339?
To fix CVE-2015-5339, update to Moodle version 2.7.11, 2.8.9, or 2.9.3 or later.
Which versions of Moodle are affected by CVE-2015-5339?
Affected versions include Moodle versions up to 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3.
What type of vulnerability is CVE-2015-5339?
CVE-2015-5339 is an access control vulnerability related to improper implementation of group-based restrictions.
Can CVE-2015-5339 be exploited remotely?
Yes, CVE-2015-5339 can be exploited by remote authenticated users to obtain sensitive course participant information.