Description: | Descriptions of external badges were open to exploitation. |
Issue summary: | Unserialize external input in badges/external.php allows object injection |
Severity/Risk: | Serious |
Versions affected: | 2.5 to 2.5.1 |
Versions fixed: | 2.5.2 |
Reported by: | Emilio Pinna |
Issue no.: | MDL-40924 |
CVE identifier: | CVE-2013-5674 |
Changes (master): | http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-40924 |