Description
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
Remediation
References
Related Vulnerabilities
Dolibarr Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-22666)
PHP Use After Free Vulnerability (CVE-2024-11235)
Python Integer Overflow or Wraparound Vulnerability (CVE-2007-4965)
Apache Tomcat Other Vulnerability (CVE-2007-2449)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (4.9.2)