Fedora Account System
Red Hat Associate
Red Hat Customer
Description: Moodle App lets mobile site-plugin JavaScript from one Moodle site read secure-storage tokens for other Moodle sites already configured in the app. A co-installed malicious Android app can open Moodle App to an attacker-controlled fake Moodle site; after the user accepts Moodle's site-change prompt, attacker site-plugin JS runs inside Moodle App and steals the victim site's webservice token Versions affected: 5.2.0 and earlier unsupported versions Versions fixed: 5.2.1