Vulnerability Description
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
CVSS Score
5.4
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | 2.8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/92042Third Party AdvisoryVDB Entry
- https://moodle.org/mod/forum/discuss.php?d=336699PatchVendor Advisory
- http://www.securityfocus.com/bid/92042Third Party AdvisoryVDB Entry
- https://moodle.org/mod/forum/discuss.php?d=336699PatchVendor Advisory
FAQ
What is CVE-2016-5014?
CVE-2016-5014 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
How severe is CVE-2016-5014?
CVE-2016-5014 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5014?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.