Cross Site Scripting - help.php

Cross Site Scripting - help.php

by wicked bob -
Number of replies: 4
http://secunia.com/advisories/12065/

Do I have to do anything about this as a Moodle Administrator?
Average of ratings: -
In reply to wicked bob

Re: Cross Site Scripting - help.php

by Petr Skoda -
Picture of Core developers Picture of Documentation writers Picture of Peer reviewers Picture of Plugin developers
You can erase help.php file from your Moodle installation directory and wait for more info...
In reply to wicked bob

Re: Cross Site Scripting - help.php

by W Page -
Hi!

This again raises the issue of some type of "vunerability  reporting" of issues which may affect Moodle.  I had raised the issue of the possiblity of creating a forum regarding security issues previously, However, it is unclear if there is a Moodler with expertise on these issues who would head and monitor this forum, therefore,
 it may be an unreasonable request at this time.

Moodle & Authentication

http://moodle.org/mod/forum/discuss.php?d=9882

WP1
In reply to wicked bob

Re: Cross Site Scripting - help.php

by Martin Dougiamas -
Picture of Core developers Picture of Documentation writers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
I've spent all day packaging a new release of Moodle which is nearly ready - Moodle 1.3.3.

It addresses this issue (and another one).

Then, as I usually do, I will post an advisory to all registered sites with information and instructions.   I don't publish this sort of information on the forums.
In reply to Martin Dougiamas

Re: Cross Site Scripting - help.php

by wicked bob -
I will download the update when you make it available and also register my moodle site.
Thanks for your diligence.