Security Announcements

 
 
My ugly mug
MSA-13-0020: Capability issue in Assignment
 
Description: The assignment module was not checking capabilities for users downloading all assignments as a zip.
Issue summary: Students can download assignments submitted by other students
Severity/Risk: Serious
Versions affected: 2.4 to 2.4.3, 2.3 to 2.3.6
Versions fixed: 2.5, 2.4.4 and 2.3.7
Reported by: Phillip Franks
Issue no.: MDL-38443
CVE identifier: CVE-2013-2079
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-38443