The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
https://bugzilla.redhat.com/show_bug.cgi?id=1335933
http://www.securitytracker.com/id/1035902
http://www.openwall.com/lists/oss-security/2016/05/17/4
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3929
Source: Mitre, NVD
Published: 2017-04-20
Updated: 2026-05-13
Base Score: 4
Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N
Severity: Medium
Base Score: 6.5
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.00379