Vulnerability in Moodle Allows Unauthorized Blog Searches
CVE-2017-7490
5.3MEDIUM
Summary
In Moodle versions 2.x and 3.x, a significant security issue arises from inadequate capability checks, permitting unauthorized users to search and access arbitrary blogs. This vulnerability compromises user privacy and exposes sensitive content that should be restricted. Site administrators are encouraged to apply necessary updates and monitor for unauthorized access to strengthen security measures.
Affected Version(s)
Moodle 2.x and 3.x Moodle 2.x and 3.x
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved