MSA-21-0039: Upgrade moodle-mlbackend-python and update its reference in /lib/mlbackend/python/classes/processor.php (upstream)

by Michael Hawkins.  

The upstream Moodle machine learning backend and its reference in /lib/mlbackend/python/classes/processor.php were upgraded, which includes some security updates.

Please note: If you are using Moodle Analytics, an upgrade to the mlbackend is required. See the Analytics settings documentation for more information about...

Leer más...

MSA-21-0038: Remote code execution risk when restoring malformed backup file

by Michael Hawkins.  

A remote code execution risk when restoring backup files was identified.


...
Severity/Risk:Serious
Versions affected:3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions
Versions fixed:3.11.4, 3.10.8 and 3.9.11
Reported by:Paul Holden
CVE identifier:CVE-2021-3943
Changes (master):http://git.moodle.org/gw?p=
Leer más...

MSA-21-0036: Quiz unreleased grade disclosure via web service

by Michael Hawkins.  

It was possible for a student to view their quiz grade before it had been released, using a quiz web service.


...
Severity/Risk:Serious
Versions affected:3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions
Versions fixed:3.11.3, 3.10.7 and 3.9.10
Reported by:Nadav Kavalerchik
CVE identifier:CVE-2021-40695
C
Leer más...

MSA-21-0036: Quiz unreleased grade disclosure via web service

by Michael Hawkins.  

It was possible for a student to view their quiz grade before it had been released, using a quiz web service.


...
Severity/Risk:Serious
Versions affected:3.11 to 3.11.2, 3.10 to 3.10.6, 3.9 to 3.9.9 and earlier unsupported versions
Versions fixed:3.11.3, 3.10.7 and 3.9.10
Reported by:Nadav Kavalerchik
CVE identifier:CVE-2021-40695
C
Leer más...