The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/05/17/4 | third party advisory mailing list |
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51369 | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1335933 | third party advisory issue tracking |
http://www.securitytracker.com/id/1035902 | third party advisory vdb entry |