Junglewise Threat Intelligence

CVE-2016-8643: Moodle improper access control in web services

CVE-2016-8643 · Severity: medium · CVSS 4.3 · Published 2017-01-20

Technologies: Moodle. Vendors: Moodle.

Executive brief

Moodle is a popular learning management system used by schools and businesses to deliver online courses. A security flaw allows site managers, who should have limited permissions, to unintentionally modify the accounts of full site administrators through automated web services. This could lead to unauthorized changes to administrative settings or account details, potentially compromising the integrity of the platform's management.

Technical details

An improper access control vulnerability (CWE-284) exists in Moodle's web services layer. The flaw allows users with the 'manager' role to modify 'administrator' user accounts when using web service functions, a privilege that should be restricted to site admins only. This vulnerability is reachable over the network and requires the attacker to have at least low-level authenticated access (manager role). Exploitation could result in unauthorized modification of administrative user data. Patches were released in Moodle versions 3.1.3, 3.0.7, and 2.7.17.

Affected products

  • Moodle Moodle 2.x, 3.0.x before 3.0.7, 3.1.x before 3.1.3

Timeline

  • 2016-11-21: advisory: Vendor advisory published by Moodle
  • 2017-01-20: disclosed: NVD publication date

References

Related threats