{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.5"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.6"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.7"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.8"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.9"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.8.10"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.9.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.9.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.9.2"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.9.3"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "2.9.4"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.0"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.0.2"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "21db825b19e84bb24c0661b551a5069970e143c4"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "296b602f2cd751cac5de6bda553db381432da704"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "f2c730fecfcc9850ea39cf53186f8b3f0a114ae1"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "68b1fd2c5500284e0afe8fda78b2e9551eb697a6"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "f4dc567e79e871b7e0aab64dd39706ac112094ac"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "be3e6f62029e26a125871d4b6bf42156cb7e512c"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "dc7b914677dcdded287671ca9eb92e0e95e9f2a0"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "1f2979d0e51c2d2a8dc535b9c84b7364016fe8d4"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "e494078a27ae8fd2f91c908d12911adb3c32e6ee"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "ae1854f55c265e2e0966de4b81636c31c641b029"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "2e8e92b0f1a21a77aadcb320d358273855193cd0"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "cbd90c01c120a199ca53b5965785c55f88834cdc"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "c948f378b9d7a819d2d430894fa9840cfe9b5590"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "b7d2ed3004ba4f165aba55e1a235f02d55f76624"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "3a325f777f9d43fda5c1dfb1287a8bf6d8e61938"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "d16cdbd81fbf07e33f55c26f0569ee1424126b59"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "6114fab93b414fcfa107d5a8fa2b35bc99d3464e"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "62e799ac84232c065790c8cab0f841e43ae038e0"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "5d35d7b8843f5f4571dd0b10ad1490cd524e67da"
            }
          ],
          "repo": "https://github.com/moodle/moodle",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify \"Exclude grade\" settings by leveraging the Non-Editing Instructor role.",
  "id": "CVE-2016-2155",
  "modified": "2026-03-13T21:56:49.376115351Z",
  "published": "2016-05-22T20:59:04.130Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://git.moodle.org/gw?p=moodle.git\u0026a=search\u0026h=HEAD\u0026st=commit\u0026s=MDL-52378"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2016/03/21/1"
    },
    {
      "type": "WEB",
      "url": "http://www.securitytracker.com/id/1035333"
    },
    {
      "type": "ADVISORY",
      "url": "https://moodle.org/mod/forum/discuss.php?d=330177"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}