Vulnerability Bulletins |
MSA-17-0012: CSRF in number of courses displayed in the course overview block |
|
| Affected software | PHP |
|
by Marina Glancy. The link changing user preference of how many courses to see in their course overview block was not protected against CSRF. This represents a minor security issue since it cant be exploited for anybodys benefit, only to create confusionsSeverity/Risk:MinorVersions affected:3.2 to 3.2.2, 3.1 to 3.1.5, 3.0 to 3.0.9, 2.7 to 2.7.19 and other unsupported versionsVersions fixed:3.2.3, 3.1.6, 3.0.10 and 2.7.20Reported by:Lukas SchmidtCVE identifier:CVE-2017-7491Changes More info: https://moodle.org/mod/forum/discuss.php?d=352355&parent=1421789 |
|






