Description
Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.
Remediation
References
Related Vulnerabilities
phpBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2002-2346)
Jboss EAP Improper Handling of Exceptional Conditions Vulnerability (CVE-2018-8039)
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-8151)