Itamar Tzadok found an issue in the group constraint checking for loginas. In some cases if a user had loginas privileges but not the site:accessallgroups capability, they could use this flaw to log in as a user not in their group. This issue affected Moodle versions 2.6, 2.5 to 2.5.4, 2.4 to 2.4.7, 2.3 to 2.3.10 and earlier unsupported versions. It has been fixed in 2.6.1, 2.5.4, 2.4.8 and 2.3.11. I have not checked if versions 1.9.19 in EPEL 5 is affected or not. According to the Moodle documentation, loginas cannot be used to log in as an administrator: http://docs.moodle.org/25/en/Capabilities/moodle/user:loginas Patch: http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-42643
Created moodle tracking bugs for this issue: Affects: fedora-all [bug 1055388] Affects: epel-all [bug 1055390]
Upstream announcement: https://moodle.org/mod/forum/discuss.php?d=252415