MSA-12-0024: Hidden information access issue

MSA-12-0024: Hidden information access issue

by Michael de Raadt -
Number of replies: 0
Topic: Data protection issue / Information disclosure by "Settings" -> "Users" -> "Enrolled users"
Severity/Risk: Minor
Versions affected: 2.2 to 2.2.2+, 2.1 to 2.1.5+
Reported by: Andreas Grupp
Issue no.: MDL-31923

CVE Identifier:

CVE-2012-2353
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-31923

Description:

Teachers without appropriate permissions were able see user access information.