Topic: | My profile block may disclose private information if used in user context |
Severity: | Minor |
Versions affected: | <2.0.2 (1.9.x not affected) |
Reported by: | Internal code review |
Issue no.: | MDL-26034 |
Solution: | Upgrade to latest version |
Workaround: | Uninstall the myprofile block and delete block/myprofile files |
Description:
The My profile block could allow disclosure of private information when placed on pages in the user context. The block was changed to show only current user information.