CVE-2016-2155

EUVD-2022-2083
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging the Non-Editing Instructor role.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Affected Products (NVD)
VendorProductVersion
moodlemoodle
2.8.0
moodlemoodle
2.8.1
moodlemoodle
2.8.2
moodlemoodle
2.8.3
moodlemoodle
2.8.4
moodlemoodle
2.8.5
moodlemoodle
2.8.6
moodlemoodle
2.8.7
moodlemoodle
2.8.8
moodlemoodle
2.8.9
moodlemoodle
2.8.10
moodlemoodle
2.9.0
moodlemoodle
2.9.1
moodlemoodle
2.9.2
moodlemoodle
2.9.3
moodlemoodle
2.9.4
moodlemoodle
3.0.0
moodlemoodle
3.0.1
moodlemoodle
3.0.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
moodle
artful
ignored
bionic
Fixed 3.0.3+dfsg-0ubuntu1
released
cosmic
Fixed 3.0.3+dfsg-0ubuntu1
released
precise
ignored
trusty
dne
wily
ignored
xenial
Fixed 3.0.3+dfsg-0ubuntu1
released
yakkety
ignored
zesty
ignored
Common Weakness Enumeration