SCORMCloud_MoodleModule icon indicating copy to clipboard operation
SCORMCloud_MoodleModule copied to clipboard

rollupregistration.php - no auth checks

Open danmarsden opened this issue 13 years ago • 0 comments

rollupregistration can be called without logging in or any capability checks - it also writes directly to a log file which could allow a malicious user to fill up diskspace with multiple calls.

danmarsden avatar Jun 26 '12 03:06 danmarsden