Moodle Permissions Privileges and Access Controls Vulnerability - CVE-2012-6098 - Vulnerability Database

Moodle Permissions Privileges and Access Controls Vulnerability - CVE-2012-6098

Medium
Reference: CVE-2012-6098
Title: Moodle Permissions Privileges and Access Controls Vulnerability
Overview:

grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19 2.1.x before 2.1.10 2.2.x before 2.2.7 2.3.x before 2.3.4 and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.