Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-06-01 12:59
Updated : 2020-12-01 06:52
NVD link : CVE-2015-3177
Mitre link : CVE-2015-3177
JSON object : View
CWE
CWE-17
DEPRECATED: Code
Products Affected
moodle
- moodle