CVE-2012-5480 Information

Description

The Database activity module in Moodle 2.1.x before 2.1.9 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants’ entries via an advanced search.

Reference

http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-35558 http://openwall.com/lists/oss-security/2012/11/19/1 http://www.securityfocus.com/bid/56505 https://moodle.org/mod/forum/discuss.php?d=216160

Share on: