Security Advisory
CVE-2016-7038
7.3
HIGH
Vulnerability Description
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
Published Date
January 20, 2017
Official Source
NIST NVD Advisory