CVE-2011-4288

Moodle <1.9.12-2.0.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

References (3)

Core 3

Scores

EPSS 0.0020
EPSS Percentile 41.7%

Details

CWE
CWE-264
Status published
Products (13)
moodle/moodle 1.9.2
moodle/moodle 1.9.3
moodle/moodle 1.9.4
moodle/moodle 1.9.5
moodle/moodle 1.9.6
moodle/moodle 1.9.7
moodle/moodle 1.9.8
moodle/moodle 1.9.9
moodle/moodle 1.9.10
moodle/moodle 1.9.11
... and 3 more
Published Jul 16, 2012
Tracked Since Feb 18, 2026