CVE-2015-5331

MEDIUM

Moodle 2.9.0-2.9.2 - Authenticated Spam Attack via Messaging API

Title source: llm
STIX 2.1

Description

Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-254
Status published
Products (4)
moodle/moodle 2.9.0
moodle/moodle 2.9.1
moodle/moodle 2.9.2
moodle/moodle 2.9.0 - 2.9.3Packagist
Published Feb 22, 2016
Tracked Since Feb 18, 2026