Vulnerability Bulletins

MSA-17-0010: External blog editing takeover

   
Affected software PHP
 
by Marina Glancy. User could edit somebody elses external blog link. The ownership of the blog would be changed to the current user, therefore compromising other people was not possibleSeverity/Risk:MinorVersions affected:3.2 to 3.2.2, 3.1 to 3.1.5, 3.0 to 3.0.9, 2.7 to 2.7.19 and other unsupported versionsVersions fixed:3.2.3, 3.1.6, 3.0.10 and 2.7.20Reported by:Vuk IvanovicCVE identifier:CVE-2017-7489Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=352353&parent=1421787