Vulnerability Details CVE-2016-3729
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.0%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2016-3729
-
cpe:2.3:a:moodle:moodle:2.7.0
-
cpe:2.3:a:moodle:moodle:2.7.1
-
cpe:2.3:a:moodle:moodle:2.7.10
-
cpe:2.3:a:moodle:moodle:2.7.11
-
cpe:2.3:a:moodle:moodle:2.7.12
-
cpe:2.3:a:moodle:moodle:2.7.13
-
cpe:2.3:a:moodle:moodle:2.7.2
-
cpe:2.3:a:moodle:moodle:2.7.3
-
cpe:2.3:a:moodle:moodle:2.7.4
-
cpe:2.3:a:moodle:moodle:2.7.5
-
cpe:2.3:a:moodle:moodle:2.7.6
-
cpe:2.3:a:moodle:moodle:2.7.7
-
cpe:2.3:a:moodle:moodle:2.7.8
-
cpe:2.3:a:moodle:moodle:2.7.9
-
cpe:2.3:a:moodle:moodle:2.8.0
-
cpe:2.3:a:moodle:moodle:2.8.1
-
cpe:2.3:a:moodle:moodle:2.8.10
-
cpe:2.3:a:moodle:moodle:2.8.11
-
cpe:2.3:a:moodle:moodle:2.8.2
-
cpe:2.3:a:moodle:moodle:2.8.3
-
cpe:2.3:a:moodle:moodle:2.8.4
-
cpe:2.3:a:moodle:moodle:2.8.5
-
cpe:2.3:a:moodle:moodle:2.8.6
-
cpe:2.3:a:moodle:moodle:2.8.7
-
cpe:2.3:a:moodle:moodle:2.8.8
-
cpe:2.3:a:moodle:moodle:2.8.9
-
cpe:2.3:a:moodle:moodle:2.9.0
-
cpe:2.3:a:moodle:moodle:2.9.1
-
cpe:2.3:a:moodle:moodle:2.9.2
-
cpe:2.3:a:moodle:moodle:2.9.3
-
cpe:2.3:a:moodle:moodle:2.9.4
-
cpe:2.3:a:moodle:moodle:2.9.5
-
cpe:2.3:a:moodle:moodle:3.0.0
-
cpe:2.3:a:moodle:moodle:3.0.1
-
cpe:2.3:a:moodle:moodle:3.0.2
-
cpe:2.3:a:moodle:moodle:3.0.3