Description
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.
Remediation
References
Related Vulnerabilities
GlassFish CVE-2016-5528 Vulnerability (CVE-2016-5528)
MySQL CVE-2016-5612 Vulnerability (CVE-2016-5612)
WordPress Plugin Uncanny Toolkit for LearnDash Cross-Site Request Forgery (3.6.3)
WordPress Plugin WordPress Backup to Dropbox Cross-Site Scripting (4.0)
WordPress Plugin Custom Fields Search by BestWebSoft Cross-Site Scripting (1.3.1)