CVE-2017-7532
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
Moodle Improper Privilege Management
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://moodle.org/mod/forum/discuss.php?d=355556
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | moodle/moodle | >=3.3.0,<3.3.1 | 3.3.1 |
| Packagist | moodle/moodle | >=3.2.0,<3.2.4 | 3.2.4 |
| Packagist | moodle/moodle | <3.1.7 | 3.1.7 |
References
- http://www.securityfocus.com/bid/99617
- https://moodle.org/mod/forum/discuss.php?d=355556
- https://nvd.nist.gov/vuln/detail/CVE-2017-7532
- https://github.com/moodle/moodle/commit/6e861be6b7d49c5ac4583ae46762a28ede5785ad
- https://github.com/moodle/moodle/commit/915f801546a5c3618feab897072c985abfce57df
- https://github.com/moodle/moodle
- https://web.archive.org/web/20210614032706/http://www.securityfocus.com/bid/99617
CWEs
CWE-269
Verify integrity in audit chain (admin only). AS-IS.