admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2012-07-20 20:38
Updated : 2023-02-12 16:24
NVD link : CVE-2012-2359
Mitre link : CVE-2012-2359
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
moodle
- moodle