CVE-2015-5338
HIGHMoodle < 2.6.11, 2.7.x < 2.7.11, 2.8.x < 2.8.9, 2.9.x < 2.9.3 - Cross-Site Request Forgery in Lesson Module
Title source: llmDescription
Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1) mod/lesson/mediafile.php or (2) mod/lesson/view.php.
References (2)
Core 2
Core References
Patch x_refsource_confirm
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-48109
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=323233
Scores
CVSS v3
8.8
EPSS
0.0012
EPSS Percentile
30.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (25)
moodle/moodle
2.7.0
moodle/moodle
2.7.1
moodle/moodle
2.7.2
moodle/moodle
2.7.3
moodle/moodle
2.7.4
moodle/moodle
2.7.5
moodle/moodle
2.7.6
moodle/moodle
2.7.7
moodle/moodle
2.7.8
moodle/moodle
2.7.9
... and 15 more
Published
Feb 22, 2016
Tracked Since
Feb 18, 2026