CVE-2015-5331

MEDIUM

Moodle 2.9.x <2.9.3 - Auth Bypass

Title source: llm

Description

Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 39.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-254
Status draft

Affected Products (4)

moodle/moodle
moodle/moodle
moodle/moodle
moodle/moodle < 2.9.3Packagist

Timeline

Published Feb 22, 2016
Tracked Since Feb 18, 2026