The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/05/17/4 | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1335933 | issue tracking third party advisory |
http://www.securitytracker.com/id/1035902 | vdb entry third party advisory |