Vulnerability Bulletins

MSA-18-0008: Users can download any file via portfolio assignment caller class

   
Affected software PHP
 
by Marina Glancy. Students who submitted assignments and exported it to portfolios can download any stored Moodle file by changing download URLSeverity/Risk:MinorVersions affected:3.4 to 3.4.2, 3.3 to 3.3.5, 3.2 to 3.2.8, 3.1 to 3.1.11 and earlier unsupported versionsVersions fixed:3.5, 3.4.3, 3.3.6, 3.2.9 and 3.1.12Reported by:Brendan CoxWorkaround:Disable portfolios until the fix is applied. Portfolios are disabled by default in MoodleCVE identifier:CVE-2018-1134Changes

More info:

https://moodle.org/mod/forum/discuss.php?d=371200&parent=1496354