MSA-15-0031: Teacher in forum can still post to "all participants" and groups they are not members of

MSA-15-0031: Teacher in forum can still post to "all participants" and groups they are not members of

by Marina Glancy -
Number of replies: 0
Description: Group access is not properly checked when posting to "all participants" in forum
Issue summary: Teacher without accessallgroups can still post to "all participants" and groups they're not members of
Severity/Risk: Minor
Versions affected: 2.7 to 2.7.9 and earlier unsupported versions
Versions fixed: 2.7.10
Reported by: David Scotson
Issue no.: MDL-50576
CVE identifier: CVE-2015-5272
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-50576