Sensitive data disclosure

Re: Sensitive data disclosure

by Tim Hunt -
Number of replies: 0
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers
This is not the right way to report Moodle security issues. See https://moodle.org/security

(But, from what I have seen so far, your tester has failed to find any real issues. They just don't understand how Moodle works of what it is doing. E.g. the think in the URL is not as session id, it is a CSRF token. The nv_user is not created by Moodle, ...)
Average of ratings: Useful (4)