5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): NONE
Msa-24-0002: forum search accepted random parameters in its url
The URL parameters accepted by forum search were not limited to the allowed parameters.
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774
- RHBZ#2264095 issue-tracking x_refsource_REDHAT
- https://moodle.org/mod/forum/discuss.php?d=455635
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774
- RHBZ#2264095 issue-tracking x_refsource_REDHAT
- https://moodle.org/mod/forum/discuss.php?d=455635
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774
- RHBZ#2264095 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://moodle.org/mod/forum/discuss.php?d=455635
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774
- RHBZ#2264095 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://moodle.org/mod/forum/discuss.php?d=455635
- RHBZ#2264095 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://moodle.org/mod/forum/discuss.php?d=455635 x_transferred
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774 x_transferred
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774
- RHBZ#2264095 issue-tracking x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://moodle.org/mod/forum/discuss.php?d=455635
- RHBZ#2264095 issue-tracking x_refsource_REDHAT x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://moodle.org/mod/forum/discuss.php?d=455635 x_transferred
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-69774 x_transferred
Affected products
- ==and 4.1.9
- ==4.3.3
- <4.2.6
- <4.1.9
- <4.3.3
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>