CVE-2016-2157: CSRF
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2157?
CVE-2016-2157 is rated as a medium severity vulnerability due to its potential to compromise administrator authentication.
How do I fix CVE-2016-2157?
To fix CVE-2016-2157, upgrade Moodle to version 2.7.13, 2.8.11, 2.9.5, or 3.0.3 or later.
Which versions of Moodle are affected by CVE-2016-2157?
CVE-2016-2157 affects Moodle versions through 2.6.11, and 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3.
What type of vulnerability is CVE-2016-2157?
CVE-2016-2157 is classified as a cross-site request forgery (CSRF) vulnerability.
Who can exploit CVE-2016-2157?
Remote attackers can exploit CVE-2016-2157 to hijack the authentication of administrators for managing assignments.