Security
Headlines
HeadlinesLatestCVEs

Tag

#git

CVE-2023-5545: Official Moodle git projects - moodle.git/search

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

CVE
#git#auth
CVE-2023-5548: Official Moodle git projects - moodle.git/search

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

CVE-2023-5546: Official Moodle git projects - moodle.git/search

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

CVE-2023-5542: Official Moodle git projects - moodle.git/search

Students in "Only see own membership" groups could see other students in the group, which should be hidden.

CVE-2023-5544: Official Moodle git projects - moodle.git/search

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

CVE-2023-5550: Official Moodle git projects - moodle.git/search

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

CVE-2023-5551: Official Moodle git projects - moodle.git/search

Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

CVE-2023-5547: Official Moodle git projects - moodle.git/search

The course upload preview contained an XSS risk for users uploading unsafe data.

CVE-2023-5541: Official Moodle git projects - moodle.git/search

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

Opinion: The Pros and Cons of the UK’s New Digital Regulation Principles 

By Daily Contributors By Liz Smith, Digital Marketing Consultant for Elsewhen – Digital technologies have transformed how we live, work, and… This is a post from HackRead.com Read the original post: Opinion: The Pros and Cons of the UK’s New Digital Regulation Principles