Information disclosure in Moodle - CVE-2016-2158

 

Information disclosure in Moodle - CVE-2016-2158

Published: May 22, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU40270
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2158
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.


Affected software

Moodle
Fedora
moodle

How to mitigate CVE-2016-2158

Install update from vendor's website.

moodle - addressed in versions 2.7.19-1.el6, 2.8.11-1.fc22, 2.9.5-1.fc23, 3.0.3-1.el7, 3.0.3-1.fc24

External References

Related Security Bulletins