CVE-2015-5272: Moodle

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

Affected products

  • Moodle Moodle: version 2.7.0 only; version 2.7.1 only; version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; version 2.7.5 only; …

Published 2016-02-22. Last modified 2026-06-17.