4

CVE-2015-2271

tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature.

Data is provided by the National Vulnerability Database (NVD)
MoodleMoodle Version <= 2.5.9
MoodleMoodle Version2.5.0
MoodleMoodle Version2.5.1
MoodleMoodle Version2.5.2
MoodleMoodle Version2.5.3
MoodleMoodle Version2.5.4
MoodleMoodle Version2.5.5
MoodleMoodle Version2.5.6
MoodleMoodle Version2.5.7
MoodleMoodle Version2.5.8
MoodleMoodle Version2.6.0
MoodleMoodle Version2.6.1
MoodleMoodle Version2.6.2
MoodleMoodle Version2.6.3
MoodleMoodle Version2.6.4
MoodleMoodle Version2.6.5
MoodleMoodle Version2.6.6
MoodleMoodle Version2.6.7
MoodleMoodle Version2.6.8
MoodleMoodle Version2.7.0
MoodleMoodle Version2.7.1
MoodleMoodle Version2.7.2
MoodleMoodle Version2.7.3
MoodleMoodle Version2.7.4
MoodleMoodle Version2.7.5
MoodleMoodle Version2.8.0
MoodleMoodle Version2.8.1
MoodleMoodle Version2.8.2
MoodleMoodle Version2.8.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.431
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N