Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | 1.9.2 (including) | 1.9.2 (including) |
Moodle | Moodle | 1.9.3 (including) | 1.9.3 (including) |
Moodle | Moodle | 1.9.4 (including) | 1.9.4 (including) |
Moodle | Moodle | 1.9.5 (including) | 1.9.5 (including) |
Moodle | Moodle | 1.9.6 (including) | 1.9.6 (including) |
Moodle | Moodle | 1.9.7 (including) | 1.9.7 (including) |
Moodle | Moodle | 1.9.8 (including) | 1.9.8 (including) |
Moodle | Moodle | 1.9.9 (including) | 1.9.9 (including) |
Moodle | Moodle | 1.9.10 (including) | 1.9.10 (including) |
Moodle | Moodle | 1.9.11 (including) | 1.9.11 (including) |
Moodle | Moodle | 2.0.0 (including) | 2.0.0 (including) |
Moodle | Moodle | 2.0.1 (including) | 2.0.1 (including) |
Moodle | Moodle | 2.0.2 (including) | 2.0.2 (including) |
Moodle | Ubuntu | hardy | * |
Moodle | Ubuntu | lucid | * |
Moodle | Ubuntu | maverick | * |
Moodle | Ubuntu | natty | * |