RSS

Moodle Security Procedures

We treat security issues in Moodle software very seriously. Even though we dedicate a lot of time designing our code to avoid such problems, it is inevitable in a project of this size that new vulnerabilities will occasionally be discovered.

We welcome reports of security issues and will work with reporters to fix problems and publicise patches to Moodle users as quickly as possible.

How can I report a security issue?

Please "Create a new issue" in the Moodle Tracker describing the problem (and solution if possible) in detail. Make sure you set the Security Level accurately to make sure that the security team sees it. Bugs classified as a "Serious security issue" will be hidden from the general public until the security team (led by Petr Skoda) is able to resolve it and publish fixes to registered Moodle sites (see below).

How can I keep my site secure?

  1. The usual way is to update your whole Moodle to the latest stable release of the version you are using. It is very safe to go from 1.8.1 to 1.8.2+, for example, at any time. CVS is a very easy way to do this.

  2. Many of the notices will include patch information. If you are fairly confident with editing scripts, then it may be easier for you to just patch the affected file.

How can I keep track of recent security issues?

  1. Register your Moodle sites with moodle.org (visit admin/index.php in your installation to see the registration button), making sure to enable the option of being notified about security issues and updates. After your registration is accepted, your email address will be automatically added to our low-volume securityalerts mailing list.

  2. Eventually, all important security issues are published to the general public via the forum on this page. You can subscribe to the RSS feed on this page to automatically add new issues in your favourite feed reader or portal.


DiscussionStarted byRepliesLast post
MSA-08-0008: KSES related issues Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Wed, Apr 16, 2008, 05:50 AM
MSA-08-0007: imported phpMyAdmin 2.11.5.1 Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Mon, Mar 31, 2008, 03:17 PM
MSA-08-0006: Moodle cookie path can not be restricted Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Sat, Jan 19, 2008, 01:58 AM
MSA-08-0005: Bypassing restriction on multiple file uploads Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Sat, Jan 19, 2008, 01:33 AM
MSA-08-0001: Access elevation in user edit form Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Thu, Jan 17, 2008, 09:49 PM
MSA-08-0003: Insufficient access control in Login as feature Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Thu, Jan 17, 2008, 09:49 PM
MSA-08-0002: register_globals=on not supported Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Thu, Jan 17, 2008, 09:49 PM
MSA-08-0004: XSS in install.php before installation Picture of Petr Škoda (škoďák) Petr Škoda (škoďák) 0 Petr Škoda (škoďák)
Thu, Jan 17, 2008, 09:49 PM