Candidate: CVE-2011-4288 PublicDate: 2012-07-16 10:28:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4288 Description: Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_moodle: upstream_moodle: needs-triage hardy_moodle: ignored (reached end-of-life) lucid_moodle: ignored (reached end-of-life) maverick_moodle: ignored (reached end-of-life) natty_moodle: ignored (reached end-of-life) oneiric_moodle: not-affected (1.9.9.dfsg2-3) precise_moodle: not-affected quantal_moodle: not-affected raring_moodle: not-affected saucy_moodle: not-affected devel_moodle: not-affected