Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2012-5473
The Database activity module in Moodle 2.1.x before 2.1.9 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group39s users via an advanced search.