VDB
Sign up
MEDIUM5.3

GHSA-cwh2-q44x-5w3c

Moodle Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability

Quick fix

GHSA-cwh2-q44x-5w3c — moodle/moodle: upgrade to the fixed version with the command below.

composer require moodle/moodle:^4.3.0-rc2

Details

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/moodle/moodle
Introduced in: 0Fixed in: 4.3.0-rc2
Fixcomposer require moodle/moodle:^4.3.0-rc2

References