CVE-2016-3729: Moodle

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.

Affected products

  • Moodle Moodle: version 2.7.0 only; version 2.7.1 only; version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; version 2.7.5 only; …

Published 2017-04-20. Last modified 2026-06-17.