Moodle 3.5.18 release notes: Difference between revisions
From MoodleDocs
mNo edit summary |
|||
Line 13: | Line 13: | ||
==Security fixes== | ==Security fixes== | ||
* [https://moodle.org/mod/forum/discuss.php?d=422307 MSA-21-0013] Quiz unreleased grade disclosure via web service | |||
* [https://moodle.org/mod/forum/discuss.php?d=422308 MSA-21-0014] Blind SQL injection possible via MNet authentication | |||
* [https://moodle.org/mod/forum/discuss.php?d=422309 MSA-21-0015] Stored XSS in quiz grading report via user ID number | |||
* [https://moodle.org/mod/forum/discuss.php?d=422310 MSA-21-0016] Files API should mitigate denial-of-service risk when adding to the draft file area | |||
==See also== | ==See also== |
Revision as of 07:45, 17 May 2021
This version of Moodle is no longer supported for general bug fixes. You are encouraged to upgrade to a supported version of Moodle.
Releases > Moodle 3.5.18 release notes
Release date: 10 May 2021
Here is the full list of fixed issues in 3.5.18.
Privacy improvement
- MDL-71460 - Change site registration notifications and newsletter subscriptions to opt-in checkbox
Security fixes
- MSA-21-0013 Quiz unreleased grade disclosure via web service
- MSA-21-0014 Blind SQL injection possible via MNet authentication
- MSA-21-0015 Stored XSS in quiz grading report via user ID number
- MSA-21-0016 Files API should mitigate denial-of-service risk when adding to the draft file area