Description
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
Remediation
References
Related Vulnerabilities
XWiki Incorrect Authorization Vulnerability (CVE-2023-26056)
MOVEit Transfer Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2026-10699)
Joomla! Core 4.x.x Security Bypass (4.0.0 - 4.2.7)
SharePoint CVE-2023-21717 Vulnerability (CVE-2023-21717)
WordPress Plugin Gallery-Video Gallery and Youtube Gallery Cross-Site Scripting (1.7.01)