Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2017-12157 CVE-2017-2642 CVE-2017-7532 |
CWE-ID | CWE-200 CWE-269 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Moodle Web applications / Other software |
Vendor | moodle.org |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU38276
Risk: Low
CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2017-12157
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to gain access to sensitive information.
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
MitigationInstall update from vendor's website.
Vulnerable software versionsMoodle: 3.0.0 - 3.3.1
External linkshttp://www.securityfocus.com/bid/100848
http://moodle.org/mod/forum/discuss.php?d=358586
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU38684
Risk: Medium
CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2017-2642
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to gain access to sensitive information.
Moodle 3.x has user fullname disclosure on the user preferences page.
MitigationInstall update from vendor's website.
Vulnerable software versionsMoodle: 3.1.0 - 3.3.1
External linkshttp://www.securityfocus.com/bid/99606
http://moodle.org/mod/forum/discuss.php?d=355554
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU38686
Risk: Medium
CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2017-7532
CWE-ID:
CWE-269 - Improper Privilege Management
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to manipulate data.
In Moodle 3.x, course creators are able to change system default settings for courses.
MitigationInstall update from vendor's website.
Vulnerable software versionsMoodle: 3.1.0 - 3.3.1
External linkshttp://www.securityfocus.com/bid/99617
http://moodle.org/mod/forum/discuss.php?d=355556
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.