Moodle 1.9.12 was released [1] and corrects the following flaws [2]: MSA-11:0013: When a teacher is assigned to a group they can view quiz reports for all students, not just the students in their group. MSA-11-0015: A vulnerability assessment done by the Acunetix Web Scanner revealed possible XSS vulnerabilities in pages of Moodle. Upstream classifies these as major security vulnerabilities. [1] http://moodle.org/news/ [2] http://moodle.org/security/
Created moodle tracking bugs for this issue Affects: fedora-all [bug 706282] Affects: epel-6 [bug 706283]
MSA-11-0013 was assigned CVE-2011-4288 MSA-11-0015 was assigned CVE-2011-4290
Current Fedora 14/15 have 1.9.14. Current Fedora 16 has 2.0.5. Current rawhide and EPEL6 have 2.1.2.