CVE Vulnerabilities

CVE-2016-2190

Published: May 22, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle*2.6.11 (including)
MoodleMoodle2.7.0 (including)2.7.0 (including)
MoodleMoodle2.7.1 (including)2.7.1 (including)
MoodleMoodle2.7.2 (including)2.7.2 (including)
MoodleMoodle2.7.3 (including)2.7.3 (including)
MoodleMoodle2.7.4 (including)2.7.4 (including)
MoodleMoodle2.7.5 (including)2.7.5 (including)
MoodleMoodle2.7.6 (including)2.7.6 (including)
MoodleMoodle2.7.7 (including)2.7.7 (including)
MoodleMoodle2.7.8 (including)2.7.8 (including)
MoodleMoodle2.7.9 (including)2.7.9 (including)
MoodleMoodle2.7.10 (including)2.7.10 (including)
MoodleMoodle2.7.11 (including)2.7.11 (including)
MoodleMoodle2.7.12 (including)2.7.12 (including)
MoodleMoodle2.8.0 (including)2.8.0 (including)
MoodleMoodle2.8.1 (including)2.8.1 (including)
MoodleMoodle2.8.2 (including)2.8.2 (including)
MoodleMoodle2.8.3 (including)2.8.3 (including)
MoodleMoodle2.8.4 (including)2.8.4 (including)
MoodleMoodle2.8.5 (including)2.8.5 (including)
MoodleMoodle2.8.6 (including)2.8.6 (including)
MoodleMoodle2.8.7 (including)2.8.7 (including)
MoodleMoodle2.8.8 (including)2.8.8 (including)
MoodleMoodle2.8.9 (including)2.8.9 (including)
MoodleMoodle2.8.10 (including)2.8.10 (including)
MoodleMoodle2.9.0 (including)2.9.0 (including)
MoodleMoodle2.9.1 (including)2.9.1 (including)
MoodleMoodle2.9.2 (including)2.9.2 (including)
MoodleMoodle2.9.3 (including)2.9.3 (including)
MoodleMoodle2.9.4 (including)2.9.4 (including)
MoodleMoodle3.0.0 (including)3.0.0 (including)
MoodleMoodle3.0.1 (including)3.0.1 (including)
MoodleMoodle3.0.2 (including)3.0.2 (including)
MoodleUbuntuartful*
MoodleUbuntuprecise*
MoodleUbuntutrusty*
MoodleUbuntuupstream*
MoodleUbuntuwily*
MoodleUbuntuyakkety*
MoodleUbuntuzesty*

References