Security Policy
This is the security policy for the Moodle plugin quiz_archiver.
Supported versions
Only the latest released version of this Moodle plugin is supported with security fixes. Please update to the newest release before reporting an issue.
Scope
Please report everything that relates to this plugin using one of the methods described below. This includes, but is not limited to:
- Capability checks that can be bypassed
- SQL / command injections
- Ability to trigger actions as unprivileged users
- Insecure handling of user inputs
General Moodle core vulnerabilities should be reported to the Moodle Security team instead.
Reporting a vulnerability
Do not open a public GitHub issue for security vulnerabilities.
Instead, report privately using one of the methods described below:
Reporting via GitHub private vulnerability reporting
To report a security issue via GitHub, please use the Report a Vulnerability function. Do not create a public GitHub issue.
Reporting via mail
You can also report via mail. To do so, please use the following contact form.
What to include in a report
- A description of the vulnerability and its impact
- Steps to reproduce (PoC code/config welcome)
- The plugin version and Moodle version affected
Process and bug bounty
You should receive an acknowledgment within 14 business days, though most likely way earlier. Once a fix is available, a new release will be published, and the reporter will be credited (unless anonymity is requested).
Please note that as a small open source project, we can not offer monetary rewards for vulnerability reports.