CVE Vulnerabilities

CVE-2016-2155

Published: May 22, 2016 | Modified: Apr 12, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify Exclude grade settings by leveraging the Non-Editing Instructor role.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle2.8.0 (including)2.8.0 (including)
MoodleMoodle2.8.1 (including)2.8.1 (including)
MoodleMoodle2.8.2 (including)2.8.2 (including)
MoodleMoodle2.8.3 (including)2.8.3 (including)
MoodleMoodle2.8.4 (including)2.8.4 (including)
MoodleMoodle2.8.5 (including)2.8.5 (including)
MoodleMoodle2.8.6 (including)2.8.6 (including)
MoodleMoodle2.8.7 (including)2.8.7 (including)
MoodleMoodle2.8.8 (including)2.8.8 (including)
MoodleMoodle2.8.9 (including)2.8.9 (including)
MoodleMoodle2.8.10 (including)2.8.10 (including)
MoodleMoodle2.9.0 (including)2.9.0 (including)
MoodleMoodle2.9.1 (including)2.9.1 (including)
MoodleMoodle2.9.2 (including)2.9.2 (including)
MoodleMoodle2.9.3 (including)2.9.3 (including)
MoodleMoodle2.9.4 (including)2.9.4 (including)
MoodleMoodle3.0.0 (including)3.0.0 (including)
MoodleMoodle3.0.1 (including)3.0.1 (including)
MoodleMoodle3.0.2 (including)3.0.2 (including)
MoodleUbuntuartful*
MoodleUbuntubionic*
MoodleUbuntucosmic*
MoodleUbuntudevel*
MoodleUbuntuesm-apps/bionic*
MoodleUbuntuesm-apps/xenial*
MoodleUbuntuprecise*
MoodleUbuntuupstream*
MoodleUbuntuwily*
MoodleUbuntuxenial*
MoodleUbuntuyakkety*
MoodleUbuntuzesty*

References