Moodle 1.9.8 Tackles Security Vulnerabilities

Moodle has released an update to its open source learning management system for Mac OS X, Windows, and Linux. Moodle 1.9.8 includes a number of small improvements and bug fixes but also addresses nine security vulnerabilities, including two that Moodle developers have labeled as "critical" and five as "major." Moodle has also released a parallel update to the 1.8 branch, version 1.8.12, which includes comparable changes.

Moodle is the most widely adopted learning management system available, with nearly 1.2 million teachers using it and more than 33.5 million users participating in more than 3.3 million courses at more than 46,000 validated sites worldwide. Moodle supports both small and large deployments (with several sites well beyond 100,000 users) and includes course management tools, various Web 2.0 technologies, online assessments, and other features common to learning management systems.

In the latest release, the two critical security issues that were addressed include a SQL injection vulnerability in the Wiki module and a forms validation problem. It also fixed problems with cross-site scripting affecting implementations where global search is enabled and a problem that would allow regular users to find the user names of others enrolled in a course. A complete list of security vulnerabilities addressed in the latest releases can be found here.)

In the category of other enhancements, version 1.9.8 improves restoration of student data in course backups and also improves SCORM module restore. Several minor fixes are also included, such as a Firefox issue with the Chameleon theme, a problem with viewing LDAP authentication settings, and an issue with statistics generation.

Moodle developers are recommending the 1.9.8 and 1.8.12 update for all current users. Further information, including a full list of bug fixes and improvements, can be found here.

About the Author

David Nagel is the former editorial director of 1105 Media's Education Group and editor-in-chief of THE Journal, STEAM Universe, and Spaces4Learning. A 30-year publishing veteran, Nagel has led or contributed to dozens of technology, art, marketing, media, and business publications.

He can be reached at [email protected]. You can also connect with him on LinkedIn at https://www.linkedin.com/in/davidrnagel/ .


Featured

  • college student using a laptop alongside an AI robot and academic icons like a graduation cap, lightbulb, and upward arrow

    Nonprofit to Pilot Agentic AI Tool for Student Success Work

    Student success nonprofit InsideTrack has joined Salesforce Accelerator – Agents for Impact, a Salesforce initiative providing technology, funding, and expertise to help nonprofits build and customize AI agents and AI-powered tools to support and scale their missions.

  • server racks, a human head with a microchip, data pipes, cloud storage, and analytical symbols

    OpenAI, Oracle Expand AI Infrastructure Partnership

    OpenAI and Oracle have announced they will develop an additional 4.5 gigawatts of data center capacity, expanding their artificial intelligence infrastructure partnership as part of the Stargate Project, a joint venture among OpenAI, Oracle, and Japan's SoftBank Group that aims to deploy 10 gigawatts of computing capacity over four years.

  • geometric pattern features abstract icons of a dollar sign, graduation cap, and document

    Maricopa Community Colleges Adopts Platform to Combat Student Application Fraud

    In an effort to secure its admissions and financial processes, Maricopa Community Colleges has partnered with A.M. Simpkins and Associates (AMSA) to implement the company's S.A.F.E (Student Application Fraudulent Examination) across the district's 10 institutions.

  • human profile with a circuit-board brain next to an open book

    Georgia State U and Operation HOPE Program Fosters AI Literacy in Underserved Youth

    A pilot program co-led by Operation HOPE and Georgia State University is working to build technical, entrepreneurial, and financial-literacy skills in Atlanta-area youth to help them thrive in the AI-powered workforce.