A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://moodle.org/mod/forum/discuss.php?d=373370 | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10890 | issue tracking third party advisory |
http://www.securityfocus.com/bid/104738 | vdb entry third party advisory |