MSA-14-0013: Unfiltered data used in Assignment web services

MSA-14-0013: Unfiltered data used in Assignment web services

by Michael de Raadt -
Number of replies: 0
Description: Assignment web service functions were not correctly cleaning function parameters allowing alteration of assignment grade related information.
Issue summary: Review mod/assign external functions
Severity/Risk: Minor
Versions affected: 2.6 to 2.6.1
Versions fixed: 2.6.2
Reported by: Eloy Lafuente
Issue no.: MDL-43468
CVE identifier: CVE-2014-2572
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-43468