First published: Wed Jun 26 2019(Updated: )
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <=3.1.17 | 3.1.18 |
composer/moodle/moodle | >=3.4.0<=3.4.8 | 3.4.9 |
composer/moodle/moodle | >=3.5.0<=3.5.5 | 3.5.6 |
composer/moodle/moodle | >=3.6.0<=3.6.3 | 3.6.4 |
Moodle Moodle | >=3.1.0<=3.1.17 | |
Moodle Moodle | >=3.4.0<=3.4.8 | |
Moodle Moodle | >=3.5.0<=3.5.5 | |
Moodle Moodle | >=3.6.0<=3.6.3 | |
>=3.1.0<=3.1.17 | ||
>=3.4.0<=3.4.8 | ||
>=3.5.0<=3.5.5 | ||
>=3.6.0<=3.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.