Log in
logo

COUNTERING CYBER THREATS

barra-separadora

Vulnerability Bulletins

MSA-19-0022: Open redirect in the mobile launch endpoint could be used to expose mobile access tokens


System information

   
Affected software PHP

Description

by Michael Hawkins. The mobile launch endpoint contained an open redirect in some circumstances, which could result in a users mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").Severity/Risk:SeriousVersions affected:3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versionsVersions fixed:3.7.2, 3.6.6 and 3.5.8Reported by:Frederik Schou

More info:

https://moodle.org/mod/forum/discuss.php?d=391036&parent=1576214

Standar resources

Property Value
CVE CVE-2019-14830.

Version history

Version Comments Date
1.0 Advisory issued 2019-09-17
Go back

Este sitio web utiliza cookies propias y de terceros para el correcto funcionamiento y visualización del sitio web por parte del usuario, así como la recogida de estadísticas. Si continúa navegando, consideramos que acepta su uso. Puede cambiar la configuración u obtener más información. Modificar configuración