MSA-19-0010: All messaging conversations could be viewed

by Michael Hawkins.  

A web service fetching messages was not restricted to the current user's conversations.


...
Severity/Risk:Serious
Versions affected:3.6 to 3.6.3
Versions fixed:3.7, 3.6.4
Reported by:Mazen Gamal
Workaround:Disable the messaging system until the fix is applied.
CVE identifier:CVE-2019-10132
Changes (master):http://git.moodle.org/gw?p=
Register to read more...

MSA-19-0011: Open redirect in upload cohorts page

by Michael Hawkins.  

The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.3, 3.5 to 3.5.5, 3.4 to 3.4.8, 3.1 to 3.1.17 and earlier unsupported versions
Versions fixed:3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18
Reported by:Lindon Wass
CVE identifier:CVE-2019-10133
Register to read more...

MSA-19-0012: Private files uploaded via incoming mail processing could bypass quota restrictions

by Michael Hawkins.  

The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.3, 3.5 to 3.5.5, 3.4 to 3.4.8, 3.1 to 3.1.17 and earlier unsupported versions
Versions fixed:3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18
Reported by:Guillermo Leon
Register to read more...

MSA-19-0004: Log in as functionality exposed to JavaScript risk on other users' Dashboards

by Michael Hawkins.  

Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

Please note that for versions 3.1 and 3.4 only, this...

Register to read more...

MSA-19-0005: Logged in users could view all calendar events

by Michael Hawkins.  

Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)


...
Severity/Risk:Serious
Versions affected:3.6 to 3.6.2, 3.5 to 3.5.4 and
Register to read more...

MSA-19-0006: Users could elevate their role when accessing the LTI tool on a provider site

by Michael Hawkins.  

Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.


...
Severity/Risk:Serious
Versions affected:3.6 to 3.6.2, 3.5 to 3.5.4, 3.4 to 3.4.7 and earlier unsupported versions
Versions fixed:3.6.3, 3.5.5 and 3.4.8
Reported by:Brendan Cox
CVE
Register to read more...

MSA-19-0007: Stored HTML in assignment submission comments allowed links to be opened directly

by Michael Hawkins.  

Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.2, 3.5 to 3.5.4, 3.4 to 3.4.7, 3.1 to
Register to read more...

MSA-19-0008: Secure layout contained an insecure link in Boost theme

by Michael Hawkins.  

There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.2 and 3.5 to 3.5.4
Versions fixed:3.6.3 and 3.5.5
Reported by:Martin von Löwis and Luca Bösch
CVE identifier:CVE-2019-3851
Changes (master):http://git.moodle.
Register to read more...

MSA-19-0009: get_with_capability_join/get_users_by_capability not aware of context freezing

by Michael Hawkins.  

get_with_capability_join and get_users_by_capability were not taking context freezing into account when checking user capabilities


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.2
Versions fixed:3.6.3
Reported by:Andrew Nicols
CVE identifier:CVE-2019-3852
Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&
Register to read more...

MSA-19-0001: Manage groups capability is missing XSS risk flag

by Michael Hawkins.  

The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6,
Register to read more...

MSA-19-0002: Blind SSRF Risk in /badges/mybackpack.php

by Michael Hawkins.  

The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.


...
Severity/Risk:Minor
Versions affected:3.1 to 3.1.15 and earlier unsupported versions
Versions fixed:3.1.16
Reported
Register to read more...

MSA-19-0003: User full name is not escaped in the un-linked userpix page

by Michael Hawkins.  

The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.


...
Severity/Risk:Minor
Versions affected:3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions
Versions
Register to read more...

MSA-18-0020: Login CSRF vulnerability in login form

by Michael Hawkins.  

The login form is not protected by a token to prevent login cross-site request forgery.


...
Severity/Risk:Serious
Versions affected:3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier unsupported versions
Versions fixed:3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15
Reported by:Daniel Thatcher
CVE identifier:CVE-2018-16854
Chan
Register to read more...

MSA-18-0017: Moodle XML import of ddwtos could lead to intentional remote code execution

by Michael Hawkins.  

When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.


...
Severity/Risk:Serious
Versions affected:3.5 to 3.5.1, 3.4 to 3.4.4, 3.1 to 3.1.13 and
Register to read more...

MSA-18-0018: QuickForm library remote code vulnerability (upstream)

by Michael Hawkins.  

A security vulnerability was reported against QuickForm, a third party library used by Moodle. Although no attack vector was identified within our software, Moodle has updated to patched versions of QuickForm as a precaution.


...
Severity/Risk:Minor
Versions affected:3.5 to 3.5.1, 3.4 to 3.4.4, 3.3 to 3.3.7, 3.1 to 3.1.13 and
Register to read more...

MSA-18-0019: Boost theme - blog search GET parameter insufficiently filtered

by Michael Hawkins.  

The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected XSS if a user followed a malicious link containing JavaScript in the search parameter.


...
Severity/Risk:Minor
Versions affected:3.5 to 3.5.1, 3.4 to 3.4.4, 3.3 to 3.3.7 and
Register to read more...

MSA-18-0014: Privacy data exports include log data

by Michael Hawkins.  

No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester. Note this may be a serious privacy consideration for sites processing data exports.


...
Severity/Risk:Minor
Versions affected:3.5, 3.4.3, 3.3 to 3.3.6
Versions fixed:3.5.1, 3.4.4, 3.3.7
Reported by:
Register to read more...

MSA-18-0015: Web service core_course_get_categories may return invisible categories

by Michael Hawkins.  

It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories. Note this only affects cases where a user has access to manage categories, but does not also have permission to view hidden categories.


...
Severity/Risk:Minor
Versions affected:3.5
Register to read more...

MSA-18-0016: Quiz question bank import preview could execute JavaScript

by Michael Hawkins.  

When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.


...
Severity/Risk:Minor
Versions affected:3.5, 3.4 to 3.4.3, 3.3 to 3.3.6, 3.2 to 3.2.9, 3.1 to 3.1.12 and earlier unsupported versions
Versions fixed:3.5.1, 3.4.4,
Register to read more...

MSA-18-0007: Calculated question type allows remote code execution by Question authors

by Marina Glancy.  

Teacher creating Calculated question can intentionally cause remote code execution on server


...
Severity/Risk:Serious
Versions affected:3.4 to 3.4.2, 3.3 to 3.3.5, 3.2 to 3.2.8, 3.1 to 3.1.11 and earlier unsupported versions
Versions fixed:3.5, 3.4.3, 3.3.6, 3.2.9 and 3.1.12
Reported by:Robin Peraglie
CVE identifier:CVE-2018-1133
Cha
Register to read more...

More Articles...