7.5
CVSSv3

CVE-2015-5267

Published: 22/02/2016 Updated: 01/12/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

lib/moodlelib.php in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote malicious users to predict password-recovery tokens via a brute-force approach.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.9.1

moodle moodle 2.9.0

moodle moodle 2.8.1

moodle moodle 2.8.0

moodle moodle 2.7.2

moodle moodle 2.7.1

moodle moodle 2.8.5

moodle moodle 2.8.4

moodle moodle 2.7.6

moodle moodle 2.7.5

moodle moodle 2.8.3

moodle moodle 2.8.2

moodle moodle 2.7.4

moodle moodle 2.7.3

moodle moodle 2.8.7

moodle moodle 2.8.6

moodle moodle 2.7.9

moodle moodle 2.7.8

moodle moodle 2.7.7

moodle moodle 2.7.0

moodle moodle