VULNERABILITY INTELLIGENCE

CVE-2011-4288

CVSS score4 MEDIUM
EPSS probability1.67%
CISA KEVNot currently listed
Published2012-07-16
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:S/C:P/I:N/A:N

Description

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

Primary references