A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
- | 3.6.4 |