CVE-2011-4296
Publication date 16 July 2012
Last updated 24 July 2024
Ubuntu priority
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.