Authorization Flaw in Moodle Affects Instructor Group Permissions
CVE-2019-10189
4MEDIUM
What is CVE-2019-10189?
A vulnerability in Moodle allows instructors in an assignment group to modify group overrides for other groups within the same assignment, potentially leading to unauthorized access and modifications to assessments. This flaw affects Moodle versions prior to 3.7.1, 3.6.5, and 3.5.7, raising significant concerns regarding proper access controls among instructors.
Affected Version(s)
moodle 3.7.1
moodle 3.6.5
moodle 3.5.7