Medium severity4.3NVD Advisory· Published Feb 22, 2016· Updated Jun 17, 2026
CVE-2015-5331
CVE-2015-5331
Description
Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moodle/moodlePackagist | >= 2.9.0, < 2.9.3 | 2.9.3 |
Affected products
4Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-m7cc-6vhg-39wrghsaADVISORY
- moodle.org/mod/forum/discuss.phpnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2015-5331ghsaADVISORY
- github.com/moodle/moodle/commit/cd0c9ac87d75b3d893d61df21e3ecfd12c065c1fghsaWEB
News mentions
0No linked articles in our index yet.