MSA-15-0031: Teacher in forum can still post to "all participants" and groups they are not members of

MSA-15-0031: Teacher in forum can still post to "all participants" and groups they are not members of

Marina Glancy -
Atsakymų skaičius: 0
Description: Group access is not properly checked when posting to "all participants" in forum
Issue summary: Teacher without accessallgroups can still post to "all participants" and groups they're not members of
Severity/Risk: Minor
Versions affected: 2.7 to 2.7.9 and earlier unsupported versions
Versions fixed: 2.7.10
Reported by: David Scotson
Issue no.: MDL-50576
CVE identifier: CVE-2015-5272
Changes (master):