CVE-2016-2190
22.05.2016, 20:59
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.Enginsight
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 𝑥 ≤ 2.6.11 |
| moodle | moodle | 2.7.0 |
| moodle | moodle | 2.7.1 |
| moodle | moodle | 2.7.2 |
| moodle | moodle | 2.7.3 |
| moodle | moodle | 2.7.4 |
| moodle | moodle | 2.7.5 |
| moodle | moodle | 2.7.6 |
| moodle | moodle | 2.7.7 |
| moodle | moodle | 2.7.8 |
| moodle | moodle | 2.7.9 |
| moodle | moodle | 2.7.10 |
| moodle | moodle | 2.7.11 |
| moodle | moodle | 2.7.12 |
| moodle | moodle | 2.8.0 |
| moodle | moodle | 2.8.1 |
| moodle | moodle | 2.8.2 |
| moodle | moodle | 2.8.3 |
| moodle | moodle | 2.8.4 |
| moodle | moodle | 2.8.5 |
| moodle | moodle | 2.8.6 |
| moodle | moodle | 2.8.7 |
| moodle | moodle | 2.8.8 |
| moodle | moodle | 2.8.9 |
| moodle | moodle | 2.8.10 |
| moodle | moodle | 2.9.0 |
| moodle | moodle | 2.9.1 |
| moodle | moodle | 2.9.2 |
| moodle | moodle | 2.9.3 |
| moodle | moodle | 2.9.4 |
| moodle | moodle | 3.0.0 |
| moodle | moodle | 3.0.1 |
| moodle | moodle | 3.0.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References