QID 997916
Date Published: 2024-04-03
QID 997916: PHP (Composer) Security Update for moodle/moodle (GHSA-3fj7-9j8m-7r8g)
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3fj7-9j8m-7r8g for updates and patch information.
Vendor References
- GHSA-3fj7-9j8m-7r8g -
github.com/advisories/GHSA-3fj7-9j8m-7r8g
CVEs related to QID 997916
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3fj7-9j8m-7r8g | moodle/moodle |
|