MSA-16-0019: Glossary search displays entries without checking user permissions to view them

MSA-16-0019: Glossary search displays entries without checking user permissions to view them

by Marina Glancy -
Number of replies: 0
Description: When searching in a glossary entries from other glossaries could be displayed, including the modules and courses that user can not access
Issue summary: Possible to see glossary entries in courses you are not enrolled in
Severity/Risk: Minor
Versions affected: 3.1
Versions fixed: 3.1.1
Reported by: Mary Cooch
Issue no.: MDL-54844
CVE identifier: CVE-2016-5012
Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-54844