VAPT Issues reported on Moodle 3.9.2+

Re: VAPT Issues reported on Moodle 3.9.2+

by Michael Hawkins -
Number of replies: 0
Picture of Core developers Picture of Moodle HQ Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Testers
I suspect you mean have any security issues been identified in core Moodle LMS itself from one of these reports. Off the top of my head, I don't recall having ever raised a security issue for any of the automated reports I've analysed.

I imagine some of the results that relate to the specific instance being tested (like the one in the original post's screenshot) have identified issues that need fixing on that particular site (such as enabling HTTPS and other configurations), though better first ports of call would be site admins checking the Security Overview Report and going through the Security Recommendations documentation that Dan mentioned. Rather than just telling you what the problem is, those will tell you how to configure them, so are a great head start to setting up a Moodle instance securely. If an automated scan is going to be run on the site, doing those steps first will also help eliminate some of the items that the scan would otherwise legitimately raise.
Average of ratings: Useful (2)