First published: Fri Jan 20 2017(Updated: )
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=2.8.0<=2.8.12 | |
composer/moodle/moodle | >=2.9.0<=2.9.6 | 2.9.7 |
composer/moodle/moodle | >=3.0.0<=3.0.4 | 3.0.5 |
composer/moodle/moodle | =3.1.0 | 3.1.1 |
Moodle | =2.8.0 | |
Moodle | =2.8.1 | |
Moodle | =2.8.2 | |
Moodle | =2.8.3 | |
Moodle | =2.8.4 | |
Moodle | =2.8.5 | |
Moodle | =2.8.6 | |
Moodle | =2.8.7 | |
Moodle | =2.8.8 | |
Moodle | =2.8.9 | |
Moodle | =2.8.10 | |
Moodle | =2.8.11 | |
Moodle | =2.8.12 | |
Moodle | =2.9.0 | |
Moodle | =2.9.1 | |
Moodle | =2.9.2 | |
Moodle | =2.9.3 | |
Moodle | =2.9.4 | |
Moodle | =2.9.5 | |
Moodle | =2.9.6 | |
Moodle | =3.0.0 | |
Moodle | =3.0.1 | |
Moodle | =3.0.2 | |
Moodle | =3.0.3 | |
Moodle | =3.0.4 | |
Moodle | =3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5014 has been classified as a medium severity vulnerability due to the potential information leakage it can cause.
To resolve CVE-2016-5014, upgrade your Moodle installation to version 2.9.7, 3.0.5, or 3.1.1.
CVE-2016-5014 affects Moodle versions 2.8.0 through 2.8.12 and all 2.9.x and 3.0.x versions prior to the required updates.
The vulnerability allows unenrolled users to still receive event monitor notifications for courses they can no longer access.
Currently, no official workaround is recommended; upgrading to the fixed versions is advised to mitigate this vulnerability.