Boletines de Vulnerabilidades

MSA-17-0015: Course creators are able to change system default settings for courses

   
Software afectado PHP
 
di Marina Glancy. Insufficient permission check in "Site administration" tree allows users who have permission to access one page in the tree to change other settings.Severity/Risk:MinorVersions affected:3.3, 3.2 to 3.2.3, 3.1 to 3.1.6 and earlier unsupported versionsVersions fixed:3.3.1, 3.2.4 and 3.1.7Reported by:Thomas JaissonCVE identifier:CVE-2017-7532Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-59409Tracker

More info:

https://moodle.org/mod/forum/discuss.php?d=355556&parent=1434236