VYPR
High severity7.3NVD Advisory· Published Jan 20, 2017· Updated May 13, 2026

CVE-2016-7038

CVE-2016-7038

Description

In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
moodle/moodlePackagist
>= 2.7, < 2.7.162.7.16
moodle/moodlePackagist
>= 2.9, < 2.9.82.9.8
moodle/moodlePackagist
>= 3.0, < 3.0.63.0.6
moodle/moodlePackagist
>= 3.1, < 3.1.23.1.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.