{
  "schema_version": "1.7.0",
  "id": "MGASA-2015-0464",
  "published": "2015-12-05T10:03:58Z",
  "modified": "2015-12-05T09:54:09Z",
  "summary": "Updated moodle packages fix security vulnerability",
  "details": "In Moodle before 2.8.9, if guest access is open on the site,\nunauthenticated users can store Atto draft data through the editor\nautosave area, which could be exploited in a denial of service attack\n(CVE-2015-5332).\n\nIn Moodle before 2.8.9, due to a CSRF issue in the site registration form,\nit is possible to trick a site admin into sending aggregate stats to an\narbitrary domain. The attacker can send the admin a link to a site\nregistration form that will display the correct URL but, if submitted,\nwill register with another hub (CVE-2015-5335).\n\nIn Moodle before 2.8.9, the standard survey module is vulnerable to XSS\nattack by students who fill the survey (CVE-2015-5336).\n\nIn Moodle before 2.8.9, there was a reflected XSS vulnerability in the\nFlowplayer flash video player (CVE-2015-5337).\n\nIn Moodle before 2.8.9, password-protected lesson modules are subject to a\nCSRF vulnerability in the lesson login form (CVE-2015-5338).\n\nIn Moodle before 2.8.9, through web service core_enrol_get_enrolled_users\nit is possible to retrieve list of course participants who would not be\nvisible when using web site (CVE-2015-5339).\n\nIn Moodle before 2.8.9, logged in users who do not have capability 'View\navailable badges without earning them' can still access the full list of\nbadges (CVE-2015-5340).\n\nIn Moodle before 2.8.9, the SCORM module allows to bypass access\nrestrictions based on date and lets users view the SCORM contents\n(CVE-2015-5341).\n\nIn Moodle before 2.8.9, the choice module closing date can be bypassed,\nallowing users to delete or submit new responses after the choice module\nwas closed (CVE-2015-5342).\n",
  "upstream": [
    "CVE-2015-5332",
    "CVE-2015-5335",
    "CVE-2015-5336",
    "CVE-2015-5337",
    "CVE-2015-5338",
    "CVE-2015-5339",
    "CVE-2015-5340",
    "CVE-2015-5341",
    "CVE-2015-5342"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2015-0464.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=17280"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323229"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323230"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323231"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323232"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323233"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323234"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323235"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323236"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=323237"
    },
    {
      "type": "WEB",
      "url": "https://docs.moodle.org/dev/Moodle_2.8.9_release_notes"
    },
    {
      "type": "WEB",
      "url": "https://moodle.org/mod/forum/discuss.php?d=322852"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:5",
        "name": "moodle",
        "purl": "pkg:rpm/mageia/moodle?arch=source&distro=mageia-5"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.8.9-1.mga5"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
