Description: | Insufficient settings check when messaging another user opens spam possibility |
Issue summary: | Users who are not in contact list still can send messages though it is blocked in preferences |
Severity/Risk: | Minor |
Versions affected: | 2.9 to 2.9.2 |
Versions fixed: | 2.9.3 |
Reported by: | Pavel Sokolov |
Issue no.: | MDL-50426 |
CVE identifier: | CVE-2015-5331 |
Changes (master): | http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50426 |
MSA-15-0037: Possible to send a message to a user who blocked messages from non contacts
napisao/la Marina Glancy -
Broj odgovora: 0