A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
Workaround:
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2304267 | issue tracking |
https://moodle.org/mod/forum/discuss.php?d=461208 |