CVE-2016-3733: Medium severity moodle vulnerability
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3733?
CVE-2016-3733 is classified as a medium severity vulnerability that allows remote authenticated users to overwrite course identifiers.
How do I fix CVE-2016-3733?
To fix CVE-2016-3733, upgrade your Moodle installation to version 3.0.4, 2.9.6, 2.8.12, or 2.7.14.
Which versions of Moodle are affected by CVE-2016-3733?
CVE-2016-3733 affects Moodle versions 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, and 2.7 through 2.7.13.
What type of attack does CVE-2016-3733 enable?
CVE-2016-3733 enables a remote authenticated user to manipulate course identification numbers, potentially impacting course management.
Is CVE-2016-3733 a local or remote vulnerability?
CVE-2016-3733 is a remote vulnerability, as it requires authentication but allows attacks over the network.