Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-18254 META: Security overview report 2.0
  3. MDL-18019

Security Report warns for XSS when users has teacher roles

XMLWordPrintable

    • Icon: Sub-task Sub-task
    • Resolution: Won't Fix
    • Icon: Minor Minor
    • None
    • 1.9.3
    • Administration
    • None
    • MOODLE_19_STABLE
    • Moderate

      On the security report available on the latest moodle_19_weekly, the XSS trusted users warning appears when users has the Teacher role in the course context.

      While it is correct that the teacher role should be assigned to trusted users, the warning may suggest assigning teacher in courses is dangerous.

      Wouldn't be preferable to fire a more moderate message when the Teacher role is detected in course contexts or better explain the reason we warn users?

      A good starting point could be to present the list of users (showed on the Risk explanation page) with the role they have and in which context. This could help to better understand the real risk condition.

            Unassigned Unassigned
            andreabix Andrea Bicciolo
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved:

                Error rendering 'clockify-timesheets-time-tracking-reports:timer-sidebar'. Please contact your Jira administrators.