An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://moodle.org/mod/forum/discuss.php?d=371201 | vendor advisory |
http://www.securityfocus.com/bid/104307 | vdb entry third party advisory |