First published: Mon Jul 16 2012(Updated: )
Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.9.2 | |
Moodle | =1.9.3 | |
Moodle | =1.9.4 | |
Moodle | =1.9.5 | |
Moodle | =1.9.6 | |
Moodle | =1.9.7 | |
Moodle | =1.9.8 | |
Moodle | =1.9.9 | |
Moodle | =1.9.10 | |
Moodle | =1.9.11 | |
Moodle | =2.0.0 | |
Moodle | =2.0.1 | |
Moodle | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4288 has a moderate severity rating due to its potential to expose sensitive quiz reports.
To fix CVE-2011-4288, update Moodle to version 1.9.12 or later, or 2.0.3 or later.
CVE-2011-4288 affects Moodle versions 1.9.x before 1.9.12 and 2.0.x before 2.0.3.
CVE-2011-4288 is a privilege escalation vulnerability that allows unauthorized access to quiz reports.
Remote authenticated users with a teacher role can exploit CVE-2011-4288 to read quiz reports of arbitrary students.