MSA-12-0023: External enrolment plugin context check issue

MSA-12-0023: External enrolment plugin context check issue

by Michael de Raadt -
Number of replies: 0
Topic: /enrol/externallib.php method core_enrol_external .get_enrolled_users() uses undefined $context and $coursecontext's in 3 has_capability() calls
Severity: Major
Versions affected: 2.2 to 2.2.1+
Reported by: Petr Škoda
Issue no.: MDL-31178

CVE Identifier:

CVE-2012-1170
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-31178

Description:

Capability checks in the external enrolment plugin were not being performed thoroughly enough.