Forat de seguretat important a Moodle

En Martin Dougiamas ha comunicat un important forat de seguretat a Moodle:

Today our security expert Petr Skoda discovered a potential problem with one of the hidden utilityscripts in Moodle that could allow a malicious user within your site toforce an admin to unknowingly delete ALL course files.

This bug has been fixed in the CVS versions of the Moodle 1.4 branchand the main CVS trunk (the soon to be released Moodle 1.5 Beta).The download packages are also being re-created.

Since this script is not something many people need anyway, the quickest fix is simply to delete it completely from your installation.

So do that right now! The file to remove is: admin/delete.php

Autor: Oriol Morell

Em dic Oriol Morell i Jané, Enginyer informàtic de sistemes per la UOC. Sóc especialista en marketing digital, posicionament als cercadors i en desenvolupament de negocis web. Pots llegir més informació sobre mi al meu perfil a LinkedIn i pots contactar-me a oriolm(a)gmail(punt)com