|
|
Log in / Subscribe / Register

moodle: two vulnerabilities

Package(s):moodle CVE #(s):CVE-2016-0724 CVE-2016-0725
Created:January 21, 2016 Updated:February 1, 2016
Description: From the Mageia advisory:

In Moodle before 2.8.10, web services core_enrol_get_course_enrolment_methods and enrol_self_get_instance_info did not check user permission to access hidden courses (CVE-2016-0724).

In Moodle before 2.8.10, search string in course management interface was not escaped when being output creating potential for XSS attack (CVE-2016-0725).

Alerts:
Fedora FEDORA-2016-fb2597f4eb moodle 2016-02-01
Fedora FEDORA-2016-1c10ab3c35 moodle 2016-01-30
Mageia MGASA-2016-0029 moodle 2016-01-20

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds