Vulnerability in Moodle Allows Unauthorized Blog Searches
CVE-2017-7490

5.3MEDIUM

Key Information:

Vendor
Moodle
Vendor
CVE Published:
15 May 2017

Summary

In Moodle versions 2.x and 3.x, a significant security issue arises from inadequate capability checks, permitting unauthorized users to search and access arbitrary blogs. This vulnerability compromises user privacy and exposes sensitive content that should be restricted. Site administrators are encouraged to apply necessary updates and monitor for unauthorized access to strengthen security measures.

Affected Version(s)

Moodle 2.x and 3.x Moodle 2.x and 3.x

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.