vulnerabilities in my school's moodle.

vulnerabilities in my school's moodle.

by Vinicius Pereira -
Number of replies: 6

Hello, I would like to know where can I report security vulnerabilities in my school's moodle.

Average of ratings: -
In reply to Vinicius Pereira

Re: vulnerabilities in my school's moodle.

by Marcus Green -
Picture of Core developers Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers
I don't understand your question, could you expand on why you think you have vulnerabilities?
In reply to Marcus Green

Re: vulnerabilities in my school's moodle.

by Vinicius Pereira -
I was reading the source code of the login page of my schools moodle, and I want to report. In the other reply ken says to me read the FAQ and go to Security and Privacy forum...
In reply to Vinicius Pereira

Re: vulnerabilities in my school's moodle.

by Ken Task -
Picture of Particularly helpful Moodlers

There is a forum for that.  Read the FAQ and proper process for reporting/disclosing ...

https://moodle.org/mod/forum/view.php?f=1048

'We' assume you are the admin of a moodle?

'SoS', Ken


In reply to Ken Task

Re: vulnerabilities in my school's moodle.

by Vinicius Pereira -
HI, no I am a student, but I was reading de source code of my school's moodle and I find some "interesting" things, I will read de FAQ, thank you!
In reply to Vinicius Pereira

Re: vulnerabilities in my school's moodle.

by Richard Oelmann -
Picture of Core developers Picture of Plugin developers Picture of Testers
I would imagine that if, as a student, you are reading the source code of "your school's moodle", rather than the git or downloaded core Moodle code, then there are far bigger issues around the security of your school's Moodle set up than what may or may not be in the code itself!
In reply to Richard Oelmann

Re: vulnerabilities in my school's moodle.

by Vinicius Pereira -

Yes that’s right, I reported in the Moodle Tracker yesterday, but it is a problem of the institution, not about the Moodle, I will try talk to the institution to report this errors...