Vulnerability Bulletins |
MSA-17-0015: Course creators are able to change system default settings for courses |
|
| Affected software | PHP |
|
di Marina Glancy. Insufficient permission check in "Site administration" tree allows users who have permission to access one page in the tree to change other settings.Severity/Risk:MinorVersions affected:3.3, 3.2 to 3.2.3, 3.1 to 3.1.6 and earlier unsupported versionsVersions fixed:3.3.1, 3.2.4 and 3.1.7Reported by:Thomas JaissonCVE identifier:CVE-2017-7532Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-59409Tracker More info: https://moodle.org/mod/forum/discuss.php?d=355556&parent=1434236 |
|






