First published: Sun Jan 27 2013(Updated: )
lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | =2.3.0 | |
Moodle Moodle | =2.3.1 | |
Moodle Moodle | =2.3.2 | |
Moodle Moodle | =2.3.3 | |
Moodle Moodle | =2.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.