Boletines de Vulnerabilidades

MSA-20-0018: Some database module web services did not respect group settings

   
Software afectado PHP
 
by Michael Hawkins. Some database module web services allowed students to add entries within groups they did not belong to.Severity/Risk:MinorVersions affected:3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versionsVersions fixed:3.10, 3.9.3, 3.8.6, 3.7.9 and 3.5.15Reported by:Dani PalouCVE identifier:CVE-2020-25700Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-67015Tracker issue:MDL-67015 Some database

More info:

https://moodle.org/mod/forum/discuss.php?d=413938&parent=1668773