CVE-2016-2157

EUVD-2022-3696
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests that manage Assignment plugins.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Affected Products (NVD)
VendorProductVersion
moodlemoodle
𝑥
≤ 2.6.11
moodlemoodle
2.7.0
moodlemoodle
2.7.1
moodlemoodle
2.7.2
moodlemoodle
2.7.3
moodlemoodle
2.7.4
moodlemoodle
2.7.5
moodlemoodle
2.7.6
moodlemoodle
2.7.7
moodlemoodle
2.7.8
moodlemoodle
2.7.9
moodlemoodle
2.7.10
moodlemoodle
2.7.11
moodlemoodle
2.7.12
moodlemoodle
2.8.0
moodlemoodle
2.8.1
moodlemoodle
2.8.2
moodlemoodle
2.8.3
moodlemoodle
2.8.4
moodlemoodle
2.8.5
moodlemoodle
2.8.6
moodlemoodle
2.8.7
moodlemoodle
2.8.8
moodlemoodle
2.8.9
moodlemoodle
2.8.10
moodlemoodle
2.9.0
moodlemoodle
2.9.1
moodlemoodle
2.9.2
moodlemoodle
2.9.3
moodlemoodle
2.9.4
moodlemoodle
3.0.0
moodlemoodle
3.0.1
moodlemoodle
3.0.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
moodle
artful
ignored
bionic
Fixed 3.0.3+dfsg-0ubuntu1
released
cosmic
Fixed 3.0.3+dfsg-0ubuntu1
released
disco
Fixed 3.0.3+dfsg-0ubuntu1
released
precise
ignored
trusty
dne
wily
ignored
xenial
Fixed 3.0.3+dfsg-0ubuntu1
released
yakkety
ignored
zesty
ignored