FreeBSD : moodle -- multiple vulnerabilities (a430e15d-f93f-11e5-92ce-002590263bf5)

high Nessus Plugin ID 90337

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Marina Glancy reports :

- MSA-16-0003: Incorrect capability check when displaying users emails in Participants list

- MSA-16-0004: XSS from profile fields from external db

- MSA-16-0005: Reflected XSS in mod_data advanced search

- MSA-16-0006: Hidden courses are shown to students in Event Monitor

- MSA-16-0007: Non-Editing Instructor role can edit exclude checkbox in Single View

- MSA-16-0008: External function get_calendar_events return events that pertains to hidden activities

- MSA-16-0009: CSRF in Assignment plugin management page

- MSA-16-0010: Enumeration of category details possible without authentication

- MSA-16-0011: Add no referrer to links with _blank target attribute

- MSA-16-0012: External function mod_assign_save_submission does not check due dates

Solution

Update the affected packages.

See Also

https://moodle.org/security/

http://www.nessus.org/u?d6a79631

Plugin Details

Severity: High

ID: 90337

File Name: freebsd_pkg_a430e15df93f11e592ce002590263bf5.nasl

Version: 2.5

Type: local

Published: 4/5/2016

Updated: 1/4/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:moodle28, p-cpe:/a:freebsd:freebsd:moodle29, p-cpe:/a:freebsd:freebsd:moodle30, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 4/3/2016

Vulnerability Publication Date: 3/21/2016

Reference Information

CVE: CVE-2016-2151, CVE-2016-2152, CVE-2016-2153, CVE-2016-2154, CVE-2016-2155, CVE-2016-2156, CVE-2016-2157, CVE-2016-2158, CVE-2016-2159, CVE-2016-2190