A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current users conversations.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Moodle |
Moodle |
* |
3.6.4 (excluding) |
Moodle |
Ubuntu |
cosmic |
* |
Moodle |
Ubuntu |
trusty |
* |
References