CVE-2015-5341: Infoleak
modscorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5341?
CVE-2015-5341 is classified as a medium severity vulnerability due to its ability to allow authenticated users to bypass access restrictions.
How do I fix CVE-2015-5341?
To fix CVE-2015-5341, update Moodle to version 2.7.11, 2.8.9, or 2.9.3 or later.
Who is affected by CVE-2015-5341?
CVE-2015-5341 affects Moodle versions up to and including 2.6.11 and various specific versions of 2.7.x, 2.8.x, and 2.9.x.
What functionality is impacted by CVE-2015-5341?
CVE-2015-5341 impacts the availability date handling in Moodle's mod_scorm, allowing unauthorized access to SCORM content.
How can I determine if my Moodle installation is vulnerable to CVE-2015-5341?
Check the version of your Moodle installation; if it is earlier than 2.7.11, 2.8.9, or 2.9.3, it is vulnerable to CVE-2015-5341.