CyberRota
Live Feed
Return to register
Case File

CVE-2016-2158

MEDIUM · CVSS 4.3 EPSS 1.71%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-05-22 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2016-2158
Severity
MEDIUM
CVSS
4.3
EPSS
1.71%

Original Filing — NVD Description

lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by leveraging the guest role for an Ajax request.