VULNERABILITY INTELLIGENCE
CVE-2011-4288
CVSS score4 MEDIUM
EPSS probability1.67%
CISA KEVNot currently listed
Published2012-07-16
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Description
Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.