Moodle Multiple Vulnerabilities
Last Update Date:
22 Mar 2016 09:49
Release Date:
22 Mar 2016
4397
Views
RISK: Medium Risk
TYPE: Web services - Web Servers
Multiple vulnerabilities have been identified in Moodle, A remote user can exploit these vulnerabilities to obtain potentially sensitive information, bypass security controls, conduct Cross-Site Scripting attack on the targeted system.
Impact
- Cross-Site Scripting
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- versions prior to 2.7.13, 2.8.11, 2.9.5, 3.0.3
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
The vendor has issued a fix: (2.7.13, 2.8.11, 2.9.5, 3.0.3).
Vulnerability Identifier
- CVE-2016-2151
- CVE-2016-2152
- CVE-2016-2153
- CVE-2016-2154
- CVE-2016-2155
- CVE-2016-2156
- CVE-2016-2157
- CVE-2016-2158
- CVE-2016-2159
- CVE-2016-2190
Source
Related Link
Share with