MSA-14-0038: Hidden grade information exposed by web services

MSA-14-0038: Hidden grade information exposed by web services

by Marina Glancy -
Number of replies: 0
Description: User without capability to view hidden grades could retrieve grades using web services.
Issue summary: get_grades webservice exposes hidden grades to students
Severity/Risk: Serious
Versions affected: 2.7 and 2.7.2
Versions fixed: 2.8, 2.7.3
Reported by: Damyon Wiese
Issue no.: MDL-47766
Workaround: Do not enable core_grades_get_grades in web services
CVE identifier: CVE-2014-7831
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-47766