Vulnerability Bulletins

MSA-17-0012: CSRF in number of courses displayed in the course overview block

   
Affected software PHP
 
by Marina Glancy. The link changing user preference of how many courses to see in their course overview block was not protected against CSRF. This represents a minor security issue since it cant be exploited for anybodys benefit, only to create confusionsSeverity/Risk:MinorVersions affected:3.2 to 3.2.2, 3.1 to 3.1.5, 3.0 to 3.0.9, 2.7 to 2.7.19 and other unsupported versionsVersions fixed:3.2.3, 3.1.6, 3.0.10 and 2.7.20Reported by:Lukas SchmidtCVE identifier:CVE-2017-7491Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=352355&parent=1421789