SB2017072039 - Fedora 25 update for moodle
Published: July 20, 2017 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2017-2642)
The vulnerability allows a remote authenticated user to gain access to sensitive information.
Moodle 3.x has user fullname disclosure on the user preferences page.
2) Improper Privilege Management (CVE-ID: CVE-2017-7532)
The vulnerability allows a remote authenticated user to manipulate data.
In Moodle 3.x, course creators are able to change system default settings for courses.
Remediation
Install update from vendor's website.