Permissions, Privileges, and Access Controls in Moodle - CVE-2015-3179
Published: June 1, 2015 / Updated: August 9, 2020
Vulnerability identifier: #VU40731
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3179
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to manipulate data.
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access to an unconfirmed suspended account.
Affected software
Moodle
Fedora
moodle
Fedora
moodle
How to mitigate CVE-2015-3179
Install update from vendor's website.
moodle - addressed in versions 2.7.9-1.fc21, 2.8.7-1.fc22, 2.9.1-1.fc23