First published: Mon May 15 2017(Updated: )
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=2.7<2.7.20 | 2.7.20 |
composer/moodle/moodle | >=3.0<3.0.10 | 3.0.10 |
composer/moodle/moodle | >=3.1<3.1.6 | 3.1.6 |
composer/moodle/moodle | >=3.2<3.2.3 | 3.2.3 |
Moodle | =2.7.0 | |
Moodle | =2.7.0-beta | |
Moodle | =2.7.0-rc1 | |
Moodle | =2.7.0-rc2 | |
Moodle | =2.7.1 | |
Moodle | =2.7.2 | |
Moodle | =2.7.3 | |
Moodle | =2.7.4 | |
Moodle | =2.7.5 | |
Moodle | =2.7.6 | |
Moodle | =2.7.7 | |
Moodle | =2.7.8 | |
Moodle | =2.7.9 | |
Moodle | =2.7.10 | |
Moodle | =2.7.11 | |
Moodle | =2.7.12 | |
Moodle | =2.7.13 | |
Moodle | =2.7.14 | |
Moodle | =2.7.15 | |
Moodle | =2.7.16 | |
Moodle | =2.7.17 | |
Moodle | =2.7.18 | |
Moodle | =3.0.0 | |
Moodle | =3.0.0-beta | |
Moodle | =3.0.0-rc1 | |
Moodle | =3.0.0-rc2 | |
Moodle | =3.0.0-rc3 | |
Moodle | =3.0.0-rc4 | |
Moodle | =3.0.1 | |
Moodle | =3.0.2 | |
Moodle | =3.0.3 | |
Moodle | =3.0.4 | |
Moodle | =3.0.5 | |
Moodle | =3.0.6 | |
Moodle | =3.0.7 | |
Moodle | =3.0.8 | |
Moodle | =3.1.0 | |
Moodle | =3.1.0-beta | |
Moodle | =3.1.0-rc1 | |
Moodle | =3.1.0-rc2 | |
Moodle | =3.1.1 | |
Moodle | =3.1.2 | |
Moodle | =3.1.3 | |
Moodle | =3.1.4 | |
Moodle | =3.2.0 | |
Moodle | =3.2.0-beta | |
Moodle | =3.2.0-rc1 | |
Moodle | =3.2.0-rc2 | |
Moodle | =3.2.0-rc3 | |
Moodle | =3.2.0-rc4 | |
Moodle | =3.2.0-rc5 | |
Moodle | =3.2.1 | |
Moodle | =3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7489 is rated as a medium severity vulnerability due to its potential for unauthorized access and modification.
To fix CVE-2017-7489, update Moodle to version 2.7.20 or later, 3.0.10 or later, 3.1.6 or later, or 3.2.3 or later.
CVE-2017-7489 affects Moodle versions 2.7.x and 3.0.x to 3.2.x.
CVE-2017-7489 is a security vulnerability that allows remote authenticated users to take ownership of arbitrary blogs by editing external blog links.
Yes, patches are included in the updated versions of Moodle that address CVE-2017-7489.