#VU43875 Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4288
Published: July 16, 2012 / Updated: August 11, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote #AU# to gain access to sensitive information.
Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.