Junglewise Threat Intelligence

CVE-2016-8644: Moodle improper access control in course notes

CVE-2016-8644 · Severity: medium · CVSS 5.3 · Published 2017-01-20

Technologies: Moodle. Vendors: Moodle.

Executive brief

Moodle, a widely used learning management system, contains a flaw in how it manages permissions for course notes. This issue could allow unauthorized individuals to view private course notes that they should not have access to. This could lead to the exposure of sensitive educational information or student-related data.

Technical details

An improper access control vulnerability exists in Moodle versions 2.x and 3.x. The root cause is a logic error where the system performs permission checks for viewing course notes in an incorrect context. This allows a remote attacker to bypass intended access restrictions and view notes they are not authorized to see. The vulnerability is reachable over the network without authentication or user interaction. Patches have been released by the vendor to address the context-checking logic.

Affected products

  • Moodle Moodle 2.7.0 to 2.7.16, 2.8.0 to 2.8.12, 2.9.0 to 2.9.8, 3.0.0 to 3.0.6, 3.1.0 to 3.1.2

Timeline

  • 2016-11-21: advisory: Vendor advisory published by Moodle
  • 2017-01-20: disclosed: NVD publication date

References

Related threats