← Back

CVE-2015-2266

nvd nist
Published: Jun 1, 2015Modified: May 6, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:P/I:N/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obtain sensitive personal-contact and unread-message-count information via a modified URL.

Affected (29)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
Up to 2.5.9
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.5.6
Version 2.5.7
Version 2.5.8
Version 2.6.0
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.6.5
Version 2.6.6
Version 2.6.7
Version 2.6.8
Version 2.7.0
Version 2.7.1
Version 2.7.2
Version 2.7.3
Version 2.7.4
Version 2.7.5
Version 2.8.0
Version 2.8.1
Version 2.8.2
Version 2.8.3

References (6)

Timeline

No history available yet.