CVE-2016-3729

MEDIUM

Moodle <3.0.3, <2.9.5, <2.8.11, <2.7.13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/05/17/4
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1335933
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035902

Scores

CVSS v3 6.5
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-284
Status published
Products (37)
moodle/moodle 2.7.0 (4 CPE variants)
moodle/moodle 2.7.1
moodle/moodle 2.7.2
moodle/moodle 2.7.3
moodle/moodle 2.7.4
moodle/moodle 2.7.5
moodle/moodle 2.7.6
moodle/moodle 2.7.7
moodle/moodle 2.7.8
moodle/moodle 2.7.9
... and 27 more
Published Apr 20, 2017
Tracked Since Feb 18, 2026