Description
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.
Remediation
References
Related Vulnerabilities
WordPress Plugin Related Sites 'guid' Parameter SQL Injection (2.1)
WordPress Plugin Booking.com Product Helper Unspecified Vulnerability (1.0.3)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6106)
WordPress Plugin Feature Slideshow 'src' Parameter Cross-Site Scripting (1.0.6beta)