CVE-2011-4296
16.07.2012, 10:28
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.Enginsight
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 2.0.0 |
| moodle | moodle | 2.0.1 |
| moodle | moodle | 2.0.2 |
| moodle | moodle | 2.0.3 |
| moodle | moodle | 2.1.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References