Note:

If you want to create a new page for developers, you should create it on the Moodle Developer Resource site.

Moodle 3.1.12 release notes

From MoodleDocs
Important:

This content of this page has been updated and migrated to the new Moodle Developer Resources. The information contained on the page should no longer be seen up-to-date.

Why not view this page on the new site and help us to migrate more content to the new site!

This version of Moodle is no longer supported for general bug fixes. You are encouraged to upgrade to a supported version of Moodle.

Releases > Moodle 3.1.12 release notes

Release date: 17 May 2018

Here is the full list of fixed issues in 3.1.12.

Security issues

  • MSA-18-0007 Calculated question type allows remote code execution by Question authors
  • MSA-18-0008 Users can download any file via portfolio assignment caller class
  • MSA-18-0009 Portfolio forum caller class allows a user to download any file
  • MSA-18-0010 User can shift a block from Dashboard to any page
  • MSA-18-0011 User who did not agree to the site policies can see the site homepage as if they had full site access
  • MSA-18-0012 Portfolio script allows instantiation of class chosen by user

See also