3.5
CVSSv2

CVE-2015-3177

Published: 01/06/2015 Updated: 01/12/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

Moodle 2.8.x prior to 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.8.0

moodle moodle 2.8.3

moodle moodle 2.8.4

moodle moodle 2.8.5

moodle moodle 2.8.1

moodle moodle 2.8.2