Vulnerability Bulletins

MSA-17-0015: Course creators are able to change system default settings for courses

   
Affected software PHP
 
di Marina Glancy. Insufficient permission check in "Site administration" tree allows users who have permission to access one page in the tree to change other settings.Severity/Risk:MinorVersions affected:3.3, 3.2 to 3.2.3, 3.1 to 3.1.6 and earlier unsupported versionsVersions fixed:3.3.1, 3.2.4 and 3.1.7Reported by:Thomas JaissonCVE identifier:CVE-2017-7532Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-59409Tracker

More info:

https://moodle.org/mod/forum/discuss.php?d=355556&parent=1434236