Alert GCSA-25055 - Aggiornamento di sicurezza per Moodle

****************************************************************** Alert ID: GCSA-25055 data: 23 aprile 2025 titolo: Aggiornamento di sicurezza per Moodle ****************************************************************** :: Descrizione del problema Sono state rilasciate nuove versioni della piattaforma di e-learning Moodle con le quali vengono risolte varie vulnerabilita' di sicurezza. MSA-25-0013: Remote code execution risk via MimeTeX command (upstream) MSA-25-0014: User DoS and name disclosure risks via IDOR in MFA email factor revoke action MSA-25-0015: Some user data available before completing second factor with MFA enabled MSA-25-0016: Assignment submissions search on anonymous submissions reveals student identities MSA-25-0017: Self enrolment available before completing second factor with MFA enabled MSA-25-0018: CSRF risk in user tours manager allows tour duplication MSA-25-0019: IDOR in RSS block allows access to additional RSS...