Moodle 2.6.4 release notes: Difference between revisions
From MoodleDocs
(Adding issues) |
(Adding security release notes) |
||
Line 16: | Line 16: | ||
===Security issues=== | ===Security issues=== | ||
* [https://moodle.org/mod/forum/discuss.php?d=264262 MSA-14-0021] Code injection in Repositories | |||
* [https://moodle.org/mod/forum/discuss.php?d=264263 MSA-14-0022] XML External Entity vulnerability in LTI module | |||
* [https://moodle.org/mod/forum/discuss.php?d=264264 MSA-14-0023] XML External Entity vulnerability in IMSCC and IMSCP | |||
* [https://moodle.org/mod/forum/discuss.php?d=264265 MSA-14-0024] Cross-site scripting vulnerability in profile field | |||
* [https://moodle.org/mod/forum/discuss.php?d=264266 MSA-14-0025] Remote code execution in Quiz | |||
* [https://moodle.org/mod/forum/discuss.php?d=264267 MSA-14-0026] Information leak in profile and notes pages | |||
* [https://moodle.org/mod/forum/discuss.php?d=264268 MSA-14-0027] Forum group posting issue | |||
* [https://moodle.org/mod/forum/discuss.php?d=264269 MSA-14-0028] Cross-site scripting possible in external badges | |||
* [https://moodle.org/mod/forum/discuss.php?d=264270 MSA-14-0029] Cross-site scripting vulnerability in exception dialogues | |||
* [https://moodle.org/mod/forum/discuss.php?d=264273 MSA-14-0032] Cross-site scripting in advanced grading methods | |||
===Fixes and improvements=== | ===Fixes and improvements=== | ||
Revision as of 02:10, 21 July 2014
Releases > Moodle 2.6.4 release notes
Release date: 14 July, 2014
Here is the full list of fixed issues in 2.6.4.
Highlights
- MDL-41383 - File picker works when zooming in and out of browser
- MDL-45580 - PDF Annotations working with multiple attempts
API changes
- MDL-43669 - Configuration option added so that mail can be sent from noreply address exclusively
Security issues
- MSA-14-0021 Code injection in Repositories
- MSA-14-0022 XML External Entity vulnerability in LTI module
- MSA-14-0023 XML External Entity vulnerability in IMSCC and IMSCP
- MSA-14-0024 Cross-site scripting vulnerability in profile field
- MSA-14-0025 Remote code execution in Quiz
- MSA-14-0026 Information leak in profile and notes pages
- MSA-14-0027 Forum group posting issue
- MSA-14-0028 Cross-site scripting possible in external badges
- MSA-14-0029 Cross-site scripting vulnerability in exception dialogues
- MSA-14-0032 Cross-site scripting in advanced grading methods
Fixes and improvements
- MDL-45579 - Duplicate group enrolment keys for the same course are no longer allowed