lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
References
Information
Published : 2013-01-27 14:55
Updated : 2020-12-01 06:52
NVD link : CVE-2012-6102
Mitre link : CVE-2012-6102
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
moodle
- moodle