Vulnerability Bulletins |
MSA-17-0010: External blog editing takeover |
|
| Affected software | PHP |
|
by Marina Glancy. User could edit somebody elses external blog link. The ownership of the blog would be changed to the current user, therefore compromising other people was not possibleSeverity/Risk:MinorVersions affected:3.2 to 3.2.2, 3.1 to 3.1.5, 3.0 to 3.0.9, 2.7 to 2.7.19 and other unsupported versionsVersions fixed:3.2.3, 3.1.6, 3.0.10 and 2.7.20Reported by:Vuk IvanovicCVE identifier:CVE-2017-7489Changes More info: https://moodle.org/mod/forum/discuss.php?d=352353&parent=1421787 |
|






