ZeroHour

CVE-2016-3729

CVSS 3.0
6.5 medium
EPSS
1%p68
Published
()
Modified
Description

The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.

Vendors
moodle
Products
moodle
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.