Description: The referrer URL used by MFA required additional sanitizing, rather than being used directly. Issue summary: Unsafe direct use of $_SERVER['HTTP_REFERER'] in admin/tool/mfa/index.php Severity/Risk: Minor Versions affected: 4.3 to 4.3.3 Versions fixed: 4.3.4 Reported by: Petr Skoda Issue no.: MDL-80878 Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-80878
Created moodle tracking bugs for this issue: Affects: epel-all [bug 2282048] Affects: fedora-all [bug 2282047]