Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078209.html | third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081047.html | third party advisory |
https://security-tracker.debian.org/tracker/CVE-2012-1158 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1158 | issue tracking third party advisory patch |
https://access.redhat.com/security/cve/cve-2012-1158 | broken link |
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/078210.html | third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/077635.html | third party advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080712.html | third party advisory |
https://moodle.org/mod/forum/discuss.php?d=198627 | patch vendor advisory |