MSA-16-0019: Glossary search displays entries without checking user permissions to view them

by Marina Glancy.  

Description:When searching in a glossary entries from other glossaries could be displayed, including the modules and courses that user can not access
Issue summary:Possible to see glossary entries in courses you are not enrolled in
Versions affected:3.1
Versions fixed:3.1.1
Reported by:Mary Cooch
Issue no.:MDL-54844
CVE identifier:CVE-2016-5012
Changes (master):

Read more