Description
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
Remediation
References
Related Vulnerabilities
phpBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-8226)
WordPress Plugin Loginizer SQL Injection (1.6.3)
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-1202)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3546)