#VU40268 Permissions, Privileges, and Access Controls in Moodle - CVE-2016-2190
Published: May 22, 2016 / Updated: August 9, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.