lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2016-05-22 20:59
Updated : 2024-02-04 18:53
NVD link : CVE-2016-2158
Mitre link : CVE-2016-2158
CVE.ORG link : CVE-2016-2158
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor