Security-Blog
August 2026
Following 10 security issues have been resolved:
0047893: Course: Add missing permission checks for Learning Objectives-Driven Courses
0048009: SOAP Authenticated arbitrary file read
0048026: Course: Unauthorized access to settings
0048067: Authenticated RCE via MediaPool
0048123: COPage: Full Path Disclosure
0048128: SQL injection in Repository Trash
0048152: Unauthenticated PHP object injection -> RCE in the Shibboleth logout endpoint
0048153: Filesystem: Enforce extraction limits in Unzip
0048156: LTI: Unauthorized access to settings
0048158: Object title removed from permission message.
Following 10 security issues have been resolved:
0047893: Course: Add missing permission checks for Learning Objectives-Driven Courses
0048009: SOAP Authenticated arbitrary file read
0048026: Course: Unauthorized access to settings
0048067: Authenticated RCE via MediaPool
0048123: COPage: Full Path Disclosure
0048128: SQL injection in Repository Trash
0048152: Unauthenticated PHP object injection -> RCE in the Shibboleth logout endpoint
0048153: Filesystem: Enforce extraction limits in Unzip
0048156: LTI: Unauthorized access to settings
0048158: Object title removed from permission message.
Following 9 security issues have been resolved:
0047893: Course: Add missing permission checks for Learning Objectives-Driven Courses
0048009: SOAP Authenticated arbitrary file read
0048026: Course: Unauthorized access to settings
0048067: Authenticated RCE via MediaPool
0048128: SQL injection in Repository Trash
0048152: Unauthenticated PHP object injection -> RCE in the Shibboleth logout endpoint
0048153: Filesystem: Enforce extraction limits in Unzip
0048156: LTI: Unauthorized access to settings
0048158: Object title removed from permission message.
July 2026
Following 5 security issues have been resolved:
0047800: Stored XSS via HTML attribute injection
0047834: Add RBAC check for Repository Objects
0047887: SOAP: Insecure Direct Object Reference (IDOR)
0047952: Object: Remove Information on Temp File Location from Error Message
0047954: Notes: Insufficient access checks
Following 5 security issues have been resolved:
0047800: Stored XSS via HTML attribute injection
0047834: Add RBAC check for Repository Objects
0047887: SOAP: Insecure Direct Object Reference (IDOR)
0047952: Object: Remove Information on Temp File Location from Error Message
0047954: Notes: Insufficient access checks