Moodle 3.5.18 release notes: Difference between revisions
From MoodleDocs
m (→Security fixes) |
Dev Docs Bot (talk | contribs) m (Protected "Moodle 3.5.18 release notes": Developer Docs Migration ([Edit=Allow only administrators] (indefinite))) |
||
(4 intermediate revisions by 4 users not shown) | |||
Line 1: | Line 1: | ||
{{Template:Migrated|newDocId=/general/releases/3.5/3.5.18}} | |||
<p class="note">'''This version of Moodle is no longer supported for general bug fixes.''' You are encouraged to [[:en:Upgrading|upgrade]] to a supported version of Moodle.</p> | <p class="note">'''This version of Moodle is no longer supported for general bug fixes.''' You are encouraged to [[:en:Upgrading|upgrade]] to a supported version of Moodle.</p> | ||
Line 4: | Line 5: | ||
Release date: | Release date: 10 May 2021 | ||
Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%223.5.18%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 3.5.18]. | Here is [https://tracker.moodle.org/secure/IssueNavigator!executeAdvanced.jspa?jqlQuery=project+%3D+mdl+AND+resolution+%3D+fixed+AND+fixVersion+in+%28%223.5.18%22%29+ORDER+BY+priority+DESC&runQuery=true&clear=true the full list of fixed issues in 3.5.18]. | ||
==Privacy improvement== | |||
* MDL-71460 - Change site registration notifications and newsletter subscriptions to opt-in checkbox | |||
==Security fixes== | ==Security fixes== | ||
* [https://moodle.org/mod/forum/discuss.php?d=422307 MSA-21-0013] Quiz unreleased grade disclosure via web service | |||
* [https://moodle.org/mod/forum/discuss.php?d=422308 MSA-21-0014] Blind SQL injection possible via MNet authentication | |||
* [https://moodle.org/mod/forum/discuss.php?d=422309 MSA-21-0015] Stored XSS in quiz grading report via user ID number | |||
* [https://moodle.org/mod/forum/discuss.php?d=422310 MSA-21-0016] Files API should mitigate denial-of-service risk when adding to the draft file area | |||
==See also== | ==See also== |
Latest revision as of 09:09, 25 May 2022
Important:
This content of this page has been updated and migrated to the new Moodle Developer Resources. The information contained on the page should no longer be seen up-to-date. Why not view this page on the new site and help us to migrate more content to the new site! |
This version of Moodle is no longer supported for general bug fixes. You are encouraged to upgrade to a supported version of Moodle.
Releases > Moodle 3.5.18 release notes
Release date: 10 May 2021
Here is the full list of fixed issues in 3.5.18.
Privacy improvement
- MDL-71460 - Change site registration notifications and newsletter subscriptions to opt-in checkbox
Security fixes
- MSA-21-0013 Quiz unreleased grade disclosure via web service
- MSA-21-0014 Blind SQL injection possible via MNet authentication
- MSA-21-0015 Stored XSS in quiz grading report via user ID number
- MSA-21-0016 Files API should mitigate denial-of-service risk when adding to the draft file area