CVE-2016-3733: Moodle

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.

Affected products

  • Moodle Moodle: version 2.7.0 only; version 2.7.1 only; version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; version 2.7.5 only; …

Published 2017-04-20. Last modified 2026-06-17.