VULNERABILITY INTELLIGENCE
CVE-2016-3733
CVSS score4.3 MEDIUM
EPSS probability1.17%
CISA KEVNot currently listed
Published2017-04-20
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
Weakness classification
- CWE-284: Improper Access Control
Primary references
- secalert@redhat.com — Patch, Vendor Advisory
- secalert@redhat.com — Mailing List, Third Party Advisory
- secalert@redhat.com — Third Party Advisory, VDB Entry
- secalert@redhat.com — Issue Tracking, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Mailing List, Third Party Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Issue Tracking, Third Party Advisory