Security Announcements

Picture of Marina Glancy
MSA-16-0002: XSS Vulnerability in course management search
 
Description: Search string in course management interface was not escaped when being output creating potential for XSS attack
Issue summary: XSS Vulnerability in course management search
Severity/Risk: Serious
Versions affected: 3.0 to 3.0.1, 2.9 to 2.9.3 and 2.8 to 2.8.9
Versions fixed: 3.0.2, 2.9.4 and 2.8.10
Reported by: Oliveira Lima
Issue no.: MDL-52552
CVE identifier: CVE-2016-0725
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-52552
Picture of Marina Glancy
MSA-16-0001: Two enrolment-related web services don't check course visibility
 
Description: Web services core_enrol_get_course_enrolment_methods and enrol_self_get_instance_info did not check user permission to access hidden courses
Issue summary: External functions core_enrol_get_course_enrolment_methods and enrol_self_get_instance_info don't check course visibility
Severity/Risk: Minor
Versions affected: 3.0 to 3.0.1, 2.9 to 2.9.3, 2.8 to 2.8.9, 2.7 to 2.7.11 and earlier unsupported versions
Versions fixed: 3.0.2, 2.9.4, 2.8.10 and 2.7.12
Reported by: Juan Leyva
Issue no.: MDL-52072
CVE identifier: CVE-2016-0724
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-52072
Picture of Marina Glancy
MSA-15-0046: Choice module closing date can be bypassed
 
Description: Users can mock URL to delete or submit new responses after the choice module was closed
Issue summary: Users can delete and submit new responses even when the choice is closed
Severity/Risk: Minor
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Juan Leyva
Issue no.: MDL-51569
CVE identifier: CVE-2015-5342
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51569
Picture of Marina Glancy
MSA-15-0045: SCORM module allows to bypass access restrictions based on date
 
Description: Incorrect and missing handling of availability dates in mod_scorm let users to view the SCORM contents bypassing the date restriction
Issue summary: Incorrect and missing handling of availability dates in mod_scorm let users to view the SCORM contents bypassing the date restriction
Severity/Risk: Minor
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Juan Leyva
Issue no.: MDL-50837
CVE identifier: CVE-2015-5341
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50837
Picture of Marina Glancy
MSA-15-0044: Capability to view available badges is not respected
 
Description: Logged in users who do not have capability 'View available badges without earning them' can still access the full list of badges
Issue summary: Capability moodle/badges:viewbadges is not respected
Severity/Risk: Minor
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Marina Glancy
Issue no.: MDL-51684
CVE identifier: CVE-2015-5340
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51684
Picture of Marina Glancy
MSA-15-0043: Web service core_enrol_get_enrolled_users does not respect course group mode
 
Description: Through WS core_enrol_get_enrolled_users it is possible to retrieve list of course participants who would not be visible when using web site
Issue summary: core_enrol_get_enrolled_users returns all participants even with separate groups
Severity/Risk: Minor
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Daniel Palou
Issue no.: MDL-51861
CVE identifier: CVE-2015-5339
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51861
Picture of Marina Glancy
MSA-15-0042: CSRF in lesson login form
 
Description: Password-protected lesson modules are subject to CSRF vulnerability
Issue summary: CSRF in lesson login form
Severity/Risk: Minor
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Ankit Agarwal
Issue no.: MDL-48109
CVE identifier: CVE-2015-5338
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-48109
Picture of Marina Glancy
MSA-15-0041: XSS in flash video player
 
Description: XSS vulnerability caused by Flowplayer flash video player has been addressed
Issue summary: Flowplayer Reflected XSS
Severity/Risk: Serious
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Andrew Nicols
Issue no.: MDL-48085
Workaround: Use HTML5 version of the player in media filter settings
CVE identifier: CVE-2015-5337
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-48085
Picture of Marina Glancy
MSA-15-0040: Student XSS in survey
 
Description: Standard survey module is vulnerable to XSS attack by students who fill the survey
Issue summary: Student XSS in survey
Severity/Risk: Minor
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Hugh Davenport
Issue no.: MDL-49940
CVE identifier: CVE-2015-5336
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-49940
Picture of Marina Glancy
MSA-15-0039: CSRF in site registration form
 
Description: Attacker can send admin a link to site registration form that will display correct URL but, if submitted, will register with another hub
Issue summary: It is possible to trick a site/admin into sending aggregate stats to an arbitrary domain
Severity/Risk: Minor
Versions affected: 2.9 to 2.9.2, 2.8 to 2.8.8, 2.7 to 2.7.10 and earlier unsupported versions
Versions fixed: 2.9.3, 2.8.9 and 2.7.11
Reported by: Andrew Davis
Issue no.: MDL-51091
CVE identifier: CVE-2015-5335
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-51091