{"id":"MGASA-2015-0464","summary":"Updated moodle packages fix security vulnerability","details":"In Moodle before 2.8.9, if guest access is open on the site,\nunauthenticated users can store Atto draft data through the editor\nautosave area, which could be exploited in a denial of service attack\n(CVE-2015-5332).\n\nIn Moodle before 2.8.9, due to a CSRF issue in the site registration form,\nit is possible to trick a site admin into sending aggregate stats to an\narbitrary domain. The attacker can send the admin a link to a site\nregistration form that will display the correct URL but, if submitted,\nwill register with another hub (CVE-2015-5335).\n\nIn Moodle before 2.8.9, the standard survey module is vulnerable to XSS\nattack by students who fill the survey (CVE-2015-5336).\n\nIn Moodle before 2.8.9, there was a reflected XSS vulnerability in the\nFlowplayer flash video player (CVE-2015-5337).\n\nIn Moodle before 2.8.9, password-protected lesson modules are subject to a\nCSRF vulnerability in the lesson login form (CVE-2015-5338).\n\nIn Moodle before 2.8.9, through web service core_enrol_get_enrolled_users\nit is possible to retrieve list of course participants who would not be\nvisible when using web site (CVE-2015-5339).\n\nIn Moodle before 2.8.9, logged in users who do not have capability 'View\navailable badges without earning them' can still access the full list of\nbadges (CVE-2015-5340).\n\nIn Moodle before 2.8.9, the SCORM module allows to bypass access\nrestrictions based on date and lets users view the SCORM contents\n(CVE-2015-5341).\n\nIn Moodle before 2.8.9, the choice module closing date can be bypassed,\nallowing users to delete or submit new responses after the choice module\nwas closed (CVE-2015-5342).\n","modified":"2026-04-16T06:23:28.787774630Z","published":"2015-12-05T10:03:58Z","upstream":["CVE-2015-5332","CVE-2015-5335","CVE-2015-5336","CVE-2015-5337","CVE-2015-5338","CVE-2015-5339","CVE-2015-5340","CVE-2015-5341","CVE-2015-5342"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0464.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17280"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323229"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323230"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323231"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323232"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323233"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323234"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323235"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323236"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=323237"},{"type":"WEB","url":"https://docs.moodle.org/dev/Moodle_2.8.9_release_notes"},{"type":"WEB","url":"https://moodle.org/mod/forum/discuss.php?d=322852"}],"affected":[{"package":{"name":"moodle","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/moodle?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.9-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0464.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}