CVE-2016-7038
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
HIGH · CVSS 7.3
EPSS 0.00243
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0