MEDIUM
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor
Published Feb 22, 2016
4.3
MEDIUMCVSS 3.0
EPSS 1.50%
Description
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.
Affected products
No data.
OR
- ≤ 2.6.11
- 2.7.0
- 2.7.1
- 2.7.2
- 2.7.3
- 2.7.4
- 2.7.5
- 2.7.6
- 2.7.7
- 2.7.8
- 2.7.9
- 2.8.0
- 2.8.1
- 2.8.2
- 2.8.3
- 2.8.4
- 2.8.5
- 2.8.6
- 2.8.7
- 2.9.0
- 2.9.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-48371 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2015/09/21/1 mailing-listx_refsource_MLIST
- http://www.securitytracker.com/id/1033619 vdb-entryx_refsource_SECTRACK
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2300 Advisory
- https://github.com/advisories/GHSA-44xp-wj24-9xxj Advisory
- https://github.com/moodle/moodle/commit/037e05e8b266bff4835f0d2eea33ef86fb71d585
- https://github.com/moodle/moodle/commit/1d70050f33edb79b974de2509f18c943969589ea
- https://github.com/moodle/moodle/commit/40a154551fcdf0b9ea906f4d1313df29754f1fa1
- https://github.com/moodle/moodle/commit/78de2e86e8506222cf49b1cc6dc58467750ae83d
- https://moodle.org/mod/forum/discuss.php?d=320289 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-5265
- https://web.archive.org/web/20160323063809/http://www.securitytracker.com/id/1033619
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 22, 2016
Updated Aug 6, 2024
Reserved Jul 1, 2015
Link CVE-2015-5265
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-2300 GHSA-44XP-WJ24-9XXJ Assigner redhat
Published Feb 22, 2016
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2022-2300