Description
lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.
Remediation
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop Cookie Multiple SQL Injection Vulnerabilities (2.4.7)
Oracle Database Server CVE-2006-1875 Vulnerability (CVE-2006-1875)
MySQL Integer Overflow or Wraparound Vulnerability (CVE-2017-3599)
WordPress Plugin BuddyPress PHP Object Injection (2.0.2)
WordPress Plugin EELV Newsletter Multiple Vulnerabilities (4.6)