CVE-2017-2576: Input Validation
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.2.1 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.1.4 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.0.8 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.7.18
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2576?
CVE-2017-2576 has a medium severity rating due to potential impacts on user data integrity.
How do I fix CVE-2017-2576?
To fix CVE-2017-2576, upgrade to Moodle version 3.2.1 or later, or apply the patch available in the release notes.
What are the affected versions in CVE-2017-2576?
CVE-2017-2576 affects Moodle versions 2.x up to 2.7.17, along with specific 2.8.x, 2.9.x, and 3.x versions.
What type of vulnerability is CVE-2017-2576?
CVE-2017-2576 is an input validation vulnerability that could lead to improper sanitization of forum attributes.
Is there a workaround for CVE-2017-2576?
There is no official workaround for CVE-2017-2576; users are advised to update to a patched version.