Vulnerabilities > CVE-2015-3177 - Code vulnerability in Moodle

047910
CVSS 3.5 - LOW
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
moodle
CWE-17
nessus

Summary

Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-14996.NASL
    descriptionmoodle-2.7.9-1.fc21 - 2.7.9. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2015-09-16
    plugin id85956
    published2015-09-16
    reporterThis script is Copyright (C) 2015-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/85956
    titleFedora 21 : moodle-2.7.9-1.fc21 (2015-14996)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-14987.NASL
    descriptionmoodle-2.9.1-1.fc23 - 2.9.1 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2015-09-21
    plugin id86032
    published2015-09-21
    reporterThis script is Copyright (C) 2015-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/86032
    titleFedora 23 : moodle-2.9.1-1.fc23 (2015-14987)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2015-14988.NASL
    descriptionmoodle-2.8.7-1.fc22 - Latest upstream release. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2015-09-16
    plugin id85955
    published2015-09-16
    reporterThis script is Copyright (C) 2015-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/85955
    titleFedora 22 : moodle-2.8.7-1.fc22 (2015-14988)