Security and privacy

How to keep your Moodle site secure and methods for increasing privacy.

Documentation: Security, Security FAQ and Increasing privacy in Moodle
Forum moderator: Dan Poltawski

Before starting a new discussion topic, please check the Security FAQ and try a forum search.

DO NOT REPORT NEW VULNERABILITIES HERE!

New security issues should be reported in the Moodle Tracker with an appropriate security level.


Page: 1 2 3 4 5 6 7 8 9 10 11 ()
DiscussionStarted byRepliesLast post
Moodle acting as OAuth2 server Picture of Hille Hille Hille Hille 0 Hille Hille
Thu, 2 Mar 2017, 1:26 AM
Restrict Access to Categories By User Picture of William Workman William Workman 5 John Provasnik
Tue, 28 Feb 2017, 10:42 AM
Cloudflare Security Issue Picture of Matt Spurrier Matt Spurrier 1 Randy Thornton
Tue, 28 Feb 2017, 9:47 AM
Recaptcha Picture of Irrashai M Irrashai M 1 Randy Thornton
Sat, 25 Feb 2017, 7:10 AM
How to restrict users who are not using office's computer? Picture of Fung Tony Fung Tony 3 Jon Bolton
Thu, 23 Feb 2017, 8:32 PM
SQL-Injection Picture of Fabienne Neveu Fabienne Neveu 7 James McLean
Fri, 17 Feb 2017, 6:04 AM
Avoiding LDAP data in plain text when you check the source code from a browser Picture of Robespierre Galindo Robespierre Galindo 3 Randy Thornton
Thu, 16 Feb 2017, 6:50 AM
task: download all submissions is possible even when you only are allowed to assess one Picture of Jeus Perez Jeus Perez 2 Dave Perry
Mon, 13 Feb 2017, 7:13 PM
Redis Sessions Picture of John Rickard John Rickard 0 John Rickard
Fri, 10 Feb 2017, 1:30 AM
Move to secure protocol (https) issues Picture of Wes Matchett Wes Matchett 8 Ken Task
Wed, 8 Feb 2017, 8:38 AM
Use Self-Signed Certificate Picture of mimi nom mimi nom 5 mimi nom
Tue, 7 Feb 2017, 10:44 PM
Can't change a password for the student Picture of Jesse Techno Jesse Techno 2 Jesse Techno
Fri, 3 Feb 2017, 2:49 AM
PHPMailer vulnerability in no-reply address Picture of mimi nom mimi nom 4 mimi nom
Tue, 31 Jan 2017, 4:10 PM
loginhttps true = too many redirects? Picture of Christos Savva Christos Savva 8 Christos Savva
Fri, 20 Jan 2017, 5:16 PM
ClamAV Picture of Pieter Portier Pieter Portier 0 Pieter Portier
Wed, 18 Jan 2017, 10:37 PM
[Security] How to protect source code and database from hosting company Picture of Huy Lam Huy Lam 7 Dave Perry
Mon, 16 Jan 2017, 7:01 PM
"Guest user has logged in" ? Picture of g k g k 2 Ken Task
Mon, 9 Jan 2017, 12:12 AM
[Security] Moodle showed all users to Sub Category Manager Picture of Huy Lam Huy Lam 1 Emma Richardson
Sat, 7 Jan 2017, 3:27 AM
Moodle 3.1.3: Website Adminstration Security Overview Picture of Monica Franz Monica Franz 2 John Okely
Fri, 6 Jan 2017, 9:36 AM
Fun times with Poisoned Cookies! Picture of Robin Stark Robin Stark 1 Randy Thornton
Fri, 23 Dec 2016, 5:20 AM
security issue Picture of Anderson Hsu Anderson Hsu 3 Dan Marsden
Thu, 22 Dec 2016, 7:17 AM
Limit number of ip adresses per user Picture of marwa bekrar marwa bekrar 4 Robin Stark
Thu, 22 Dec 2016, 7:00 AM
SSL Proxy woes Picture of Ben Steeples Ben Steeples 20 Robin Stark
Thu, 22 Dec 2016, 6:55 AM
Permissions Issues Picture of Aretha Etienne Aretha Etienne 4 Randy Thornton
Thu, 22 Dec 2016, 1:46 AM
SAML auth with users pulled via LDAP Picture of Joel Coehoorn Joel Coehoorn 0 Joel Coehoorn
Wed, 14 Dec 2016, 2:47 AM
Gravatar Advisory: How to Protect Your Email Address and Identity Picture of Nadav Kavalerchik Nadav Kavalerchik 0 Nadav Kavalerchik
Fri, 9 Dec 2016, 4:14 AM
Caching Picture of Aretha Etienne Aretha Etienne 0 Aretha Etienne
Wed, 7 Dec 2016, 4:23 AM
How secure is using admin/tool/uploaduser/index.php Picture of callum Wood callum Wood 3 Matt Bury
Tue, 6 Dec 2016, 1:12 AM
Hiding email addresses in Moodle 2.6 forums Picture of John Edmiston John Edmiston 3 Randy Thornton
Sat, 3 Dec 2016, 7:08 AM
Allow view-only access to user list Picture of Joe Behymer Joe Behymer 5 Randy Thornton
Fri, 2 Dec 2016, 9:45 AM
"view courses without participation" - not wanted / and changed? Picture of Klaas Hobo Klaas Hobo 5 Klaas Hobo
Sat, 19 Nov 2016, 12:28 AM
help: how to get rid of these terrible infinite recaptcha loops Pieter van der Hijden Pieter van der Hijden 0 Pieter van der Hijden
Fri, 18 Nov 2016, 4:46 AM
Single sign in from a student registration portal Picture of Abdulrauf Yamta Abdulrauf Yamta 1 Christopher McCool
Fri, 18 Nov 2016, 12:42 AM
Moodle was hacked, how can I modify the index.php Picture of Louis Lawson Louis Lawson 10 Ken Task
Tue, 15 Nov 2016, 9:50 PM
Moodle was hacked, how can I modify the index.php Picture of Louis Lawson Louis Lawson 2 Ken Task
Mon, 14 Nov 2016, 12:20 PM
Access to label's files prevented by user's rights? Picture of Philippe Decloitre Philippe Decloitre 2 T W
Fri, 11 Nov 2016, 12:13 AM
I think our Moodle site just survived a serious HACK attempt RabNawaz RabNawaz Panhyar 8 RabNawaz Panhyar
Tue, 8 Nov 2016, 12:29 PM
MySQL / MariaDB / PerconaDB - Root Privilege Escalation Picture of Grant Mucha Grant Mucha 0 Grant Mucha
Fri, 4 Nov 2016, 5:39 AM
How to make sure Accounts get not shared? Max 3 IPs for 1 user Picture of Sven Faltin Sven Faltin 1 James McLean
Wed, 26 Oct 2016, 7:04 AM
Katharine Edson - How secure is to use Moodle? Picture of Katharine Edson Katharine Edson 5 Christopher McCool
Sat, 22 Oct 2016, 2:37 AM
how to restrict domain myname moodle question 3 Helen Foster
Fri, 21 Oct 2016, 3:13 PM
Can I have moodle 2.9 onward function without a single cookie? Picture of Baljé Weber Baljé Weber 0 Baljé Weber
Mon, 17 Oct 2016, 5:38 PM
Windows PowerShell of AD Users to JSON Endpoint Fails to Upload Data Picture of Tim West Tim West 0 Tim West
Mon, 17 Oct 2016, 6:59 AM
How to add/allow "unsecure" code examples as text in Moodle pages Picture of Til Edward Til Edward 9 Til Edward
Sat, 15 Oct 2016, 9:15 PM
Moodle 2.9 apache can access moodle files Picture of Zola Anderson Zola Anderson 1 Tim Hunt
Sat, 15 Oct 2016, 7:51 PM
Security Question Picture of Andrew Taylor Andrew Taylor 20 Howard Miller
Tue, 11 Oct 2016, 9:49 PM
Alternatives to reCaptcha moi!!! it is what is is... Colin Fraser 3 Rick Jerz
Sat, 24 Sep 2016, 6:20 AM
How to fix a mix of secure and insecure content? Picture of Arturs Polis Arturs Polis 3 Luke Barone
Sat, 24 Sep 2016, 2:58 AM
New Profile field not working as a course restriction Picture of Anne Sherman Anne Sherman 3 Helen Foster
Thu, 15 Sep 2016, 6:10 PM
Hiding users in grade reports Picture of bart de bie bart de bie 3 Emma Richardson
Tue, 13 Sep 2016, 9:44 PM
forgotten password stopped working with https Picture of Martin Millmore Martin Millmore 2 Martin Millmore
Tue, 13 Sep 2016, 3:37 PM
My homepage (frontpage) before login is only showing the login module Picture of Stefan Stefansson Stefan Stefansson 2 Stefan Stefansson
Tue, 6 Sep 2016, 5:41 PM
Secure Cookies Me Oliver Marugg 1 John Okely
Fri, 2 Sep 2016, 10:52 AM
IP Blocker - help Picture of Paul Baumeister Paul Baumeister 16 Ernani Veloso Freire
Thu, 1 Sep 2016, 9:48 PM
dbuser hash for password in config.php? Picture of J C J C 4 Wissam Nahas
Wed, 31 Aug 2016, 3:02 PM
Autologin with the special account Picture of Grigorii Andreev Grigorii Andreev 0 Grigorii Andreev
Sun, 28 Aug 2016, 10:06 PM
cross domain ajax in script Picture of Bradley Botkin Bradley Botkin 5 Bradley Botkin
Wed, 17 Aug 2016, 7:16 PM
Category Permissions and Restrictions Picture of David Van Thillo David Van Thillo 0 David Van Thillo
Wed, 17 Aug 2016, 2:04 AM
Moodle should not force a password change Picture of Irma Boks - Eek Irma Boks - Eek 6 Irma Boks - Eek
Wed, 10 Aug 2016, 11:05 PM
Captcha alternatives? Picture of Tom Litchfield Tom Litchfield 7 Visti Larsen
Thu, 4 Aug 2016, 4:35 PM
Issues with a virus in Moodle 3.0.2+ Picture of Luis Pu Luis Pu 7 Ken Task
Wed, 3 Aug 2016, 2:49 AM
Read Only Site Picture of Kehinde Okesanjo Kehinde Okesanjo 9 Antonio Negro
Sat, 30 Jul 2016, 8:31 PM
Httpoxy vulnerabilities in php addressed? Picture of Jerry Lau Jerry Lau 1 Ken Task
Fri, 29 Jul 2016, 8:21 AM
Password Security in moodle 2.9 or greater Picture of Sanmeet Singh Sanmeet Singh 4 Sanmeet Singh
Tue, 19 Jul 2016, 2:49 PM
SSL certificate issues Picture of raghav agarwal raghav agarwal 23 James McLean
Tue, 19 Jul 2016, 7:52 AM
Restricting Access to URL in course Picture of philipp lesmana philipp lesmana 0 philipp lesmana
Thu, 14 Jul 2016, 3:21 AM
Installing ssl certificates in moodle server Picture of Christine Mburu Christine Mburu 2 Linda Petty
Wed, 13 Jul 2016, 4:53 PM
Server breached front-end - malicious files uploaded Picture of Michael Iscool Michael Iscool 19 Ken Task
Fri, 8 Jul 2016, 9:58 PM
Is the unoconv installation a security risk? Picture of Matthew Davidson Matthew Davidson 19 Ken Task
Fri, 8 Jul 2016, 5:56 AM
Should I use SSL for Login? Why not? Picture of Paul L Paul L 8 Dave Perry
Thu, 23 Jun 2016, 9:01 PM
Remove login link from pages or disable logging in for users Picture of Jordan Floyd Jordan Floyd 4 Leticia Dark-rose
Tue, 21 Jun 2016, 12:04 PM
setup https via F5 Picture of Jaifar Al Shizawi Jaifar Al Shizawi 2 Bret Miller
Mon, 13 Jun 2016, 10:35 PM
How to hide/disable courses and quiz? Picture of Lucilla Wang Lucilla Wang 17 Lucilla Wang
Mon, 6 Jun 2016, 10:28 AM
SECURITY WARNING! (moodledata) Picture of Can Yasa Can Yasa 3 Can Yasa
Thu, 2 Jun 2016, 9:16 AM
Making students invisible to each other. Picture of Shoned Jones Shoned Jones 2 Richard Oelmann
Wed, 1 Jun 2016, 12:10 AM
Moodle Security Picture of Ben Keough Ben Keough 5 James McLean
Mon, 30 May 2016, 7:49 AM
Reset of admin password Picture of David Paige David Paige 9 Ranil Peiris
Thu, 26 May 2016, 7:46 AM
Google keyword in Japanese characters for my moodle site Picture of Milan Mihajlov Milan Mihajlov 11 Guillermo Madero
Thu, 19 May 2016, 11:14 PM
Security for self enrolment and enrolment keys Picture of Alice Constable Alice Constable 2 Alice Constable
Tue, 17 May 2016, 10:34 PM
Bots are knocking our guest door ? Picture of Antti Peltonen Antti Peltonen 0 Antti Peltonen
Tue, 17 May 2016, 7:59 PM
Assigning a password Picture of Íde O'Neill Íde O'Neill 2 Emma Richardson
Mon, 16 May 2016, 11:24 PM
Harold Nartey - Is Moodle Secure to Use? Picture of Harold Nartey Harold Nartey 1 Mike Churchward
Fri, 13 May 2016, 10:58 PM
Virtual schools/courses hidden from other groups/cohorts? Picture of Dave S Dave S 0 Dave S
Thu, 12 May 2016, 6:27 AM
Limit the number of users into a group Picture of Paul Lemarchand Paul Lemarchand 1 Sebastian Wz
Wed, 11 May 2016, 4:19 PM
Allow (Deny access) in Browse list of users Picture of Wes Sykes Wes Sykes 4 Blair F.
Thu, 28 Apr 2016, 2:27 AM
After Upgrade to 3.0, SSL No Longer Working Picture of Greg Dietrich Greg Dietrich 1 James McLean
Wed, 27 Apr 2016, 9:26 AM
Secure PHP Configuration Settings for Moodle Picture of Calvin Bu Calvin Bu 3 Ken Task
Tue, 26 Apr 2016, 10:30 PM
Comment request on vulnerability results Picture of Panagiotis Petasis Panagiotis Petasis 7 Richard Oelmann
Mon, 25 Apr 2016, 11:55 PM
Security overview, some questions and question on backup Picture of John Rambo John Rambo 4 Emma Richardson
Wed, 20 Apr 2016, 7:01 PM
Customize user privacy - on user-level Picture of Marjan Milošević Marjan Milošević 1 Devon Ritter
Thu, 14 Apr 2016, 12:16 AM
Possible Exploit - Accessing the Main Admins account through the CLI Picture of Alex Legg Alex Legg 6 Alex Legg
Wed, 13 Apr 2016, 5:59 PM
Missing Secure Attribute in Encrypted Session (SSL) Cookie Picture of Vinod Kumar Vinod Kumar 2 Vinod Kumar
Wed, 13 Apr 2016, 1:25 PM
Additional security measures for Moodle Picture of John Rambo John Rambo 8 Matt Bury
Wed, 13 Apr 2016, 4:57 AM
Visitors can access lesson video by copying link Picture of prashant gupta prashant gupta 9 Guillermo Madero
Tue, 12 Apr 2016, 12:47 AM
"Invalid Login" if country code is lowercase Picture of Derek Chaplin Derek Chaplin 0 Derek Chaplin
Sat, 9 Apr 2016, 12:38 AM
Is it possible to edit the Logs and specially the admin Logs Picture of Osama Hasan Osama Hasan 2 Richard Oelmann
Thu, 7 Apr 2016, 1:04 AM
Moodle does not restrict file types for uploads??? Security Risk??? Picture of Rob Barnett Rob Barnett 17 javier D
Wed, 30 Mar 2016, 4:27 AM
How do you secure email addresses? Picture of Paul Wakelam Paul Wakelam 10 Richard Lisle
Wed, 23 Mar 2016, 7:34 PM
Hide courses and categories to specific role Picture of Renato Marchesani Renato Marchesani 3 Howard Miller
Sat, 19 Mar 2016, 10:47 PM
access to server lost Picture of Hicham Doumali Hicham Doumali 3 Hicham Doumali
Fri, 18 Mar 2016, 10:41 PM
Page: 1 2 3 4 5 6 7 8 9 10 11 ()