Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not consider dont send attributes during hub registration, which allows remote hubs to obtain sensitive site information by reading form data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | 2.1.0 (including) | 2.1.0 (including) |
Moodle | Moodle | 2.1.1 (including) | 2.1.1 (including) |
Moodle | Moodle | 2.1.2 (including) | 2.1.2 (including) |
Moodle | Moodle | 2.1.3 (including) | 2.1.3 (including) |
Moodle | Moodle | 2.1.4 (including) | 2.1.4 (including) |
Moodle | Moodle | 2.1.5 (including) | 2.1.5 (including) |
Moodle | Moodle | 2.1.6 (including) | 2.1.6 (including) |
Moodle | Moodle | 2.1.7 (including) | 2.1.7 (including) |
Moodle | Moodle | 2.1.8 (including) | 2.1.8 (including) |
Moodle | Moodle | 2.1.9 (including) | 2.1.9 (including) |
Moodle | Moodle | 2.1.10 (including) | 2.1.10 (including) |
Moodle | Ubuntu | artful | * |
Moodle | Ubuntu | bionic | * |
Moodle | Ubuntu | cosmic | * |
Moodle | Ubuntu | disco | * |
Moodle | Ubuntu | eoan | * |
Moodle | Ubuntu | esm-apps/bionic | * |
Moodle | Ubuntu | esm-apps/xenial | * |
Moodle | Ubuntu | lucid | * |
Moodle | Ubuntu | precise | * |
Moodle | Ubuntu | quantal | * |
Moodle | Ubuntu | raring | * |
Moodle | Ubuntu | saucy | * |
Moodle | Ubuntu | trusty | * |
Moodle | Ubuntu | upstream | * |
Moodle | Ubuntu | utopic | * |
Moodle | Ubuntu | vivid | * |
Moodle | Ubuntu | wily | * |
Moodle | Ubuntu | xenial | * |
Moodle | Ubuntu | yakkety | * |
Moodle | Ubuntu | zesty | * |