Boletines de Vulnerabilidades

MSA-17-0010: External blog editing takeover

   
Software afectado PHP
 
by Marina Glancy. User could edit somebody elses external blog link. The ownership of the blog would be changed to the current user, therefore compromising other people was not possibleSeverity/Risk:MinorVersions affected:3.2 to 3.2.2, 3.1 to 3.1.5, 3.0 to 3.0.9, 2.7 to 2.7.19 and other unsupported versionsVersions fixed:3.2.3, 3.1.6, 3.0.10 and 2.7.20Reported by:Vuk IvanovicCVE identifier:CVE-2017-7489Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=352353&parent=1421787