Security announcements

MSA-16-0001: Two enrolment-related web services don't check course visibility

 
Picture of Marina Glancy
MSA-16-0001: Two enrolment-related web services don't check course visibility
 
Description: Web services core_enrol_get_course_enrolment_methods and enrol_self_get_instance_info did not check user permission to access hidden courses
Issue summary: External functions core_enrol_get_course_enrolment_methods and enrol_self_get_instance_info don't check course visibility
Severity/Risk: Minor
Versions affected: 3.0 to 3.0.1, 2.9 to 2.9.3, 2.8 to 2.8.9, 2.7 to 2.7.11 and earlier unsupported versions
Versions fixed: 3.0.2, 2.9.4, 2.8.10 and 2.7.12
Reported by: Juan Leyva
Issue no.: MDL-52072
CVE identifier: CVE-2016-0724
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-52072