← Back

CVE-2011-4288

nvd nist
Published: Jul 16, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:P/I:N/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

Affected (13)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
Version 1.9.10
Version 1.9.11
Version 1.9.2
Version 1.9.3
Version 1.9.4
Version 1.9.5
Version 1.9.6
Version 1.9.7
Version 1.9.8
Version 1.9.9
Version 2.0.0
Version 2.0.1
Version 2.0.2

Related CWEs

References (6)

Timeline

No history available yet.