Bug 1390193 (CVE-2016-7919) - CVE-2016-7919 moodle: Information disclosure in the Administration panel function
Summary: CVE-2016-7919 moodle: Information disclosure in the Administration panel func...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-7919
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1390194 1390195
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-10-31 12:59 UTC by Andrej Nemec
Modified: 2019-09-29 13:59 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2017-10-31 19:33:20 UTC
Embargoed:


Attachments (Terms of Use)

Description Andrej Nemec 2016-10-31 12:59:35 UTC
Moodle 3.1.2 allows remote attackers to obtain sensitive information
via unspecified vectors, related to a "SQL Injection" issue affecting
the Administration panel function in the installation process
component.

References:

https://www.youtube.com/watch?v=pQS1GdQ3CBc

This is not yet available at:

https://moodle.org/security/

Comment 1 Andrej Nemec 2016-10-31 13:00:08 UTC
Created moodle tracking bugs for this issue:

Affects: fedora-all [bug 1390194]
Affects: epel-7 [bug 1390195]


Note You need to log in before you can comment on or make changes to this bug.