CVE-2016-2190: Medium severity moodle vulnerability
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2190?
The severity of CVE-2016-2190 is classified as medium because it allows an attacker to access sensitive information.
How do I fix CVE-2016-2190?
To fix CVE-2016-2190, update Moodle to at least version 2.7.13, 2.8.11, 2.9.5, or 3.0.3.
What versions of Moodle are affected by CVE-2016-2190?
Moodle versions up to 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 are affected by CVE-2016-2190.
Is CVE-2016-2190 easily exploitable?
Yes, CVE-2016-2190 can be easily exploited by remote attackers who can access referer logs.
What types of information can be compromised due to CVE-2016-2190?
CVE-2016-2190 allows attackers to obtain sensitive URL information that could potentially lead to further exploitation.