MSA-16-0025: Capability to view course notes is checked in the wrong context

by Marina Glancy.  

Description:Incorrect capability check may have allowed users to view course notes when they had site-wide permission which was revoked inside a course
Issue summary:Notes has_capability check not called for correct context
Versions affected:3.1 to 3.1.2, 3.0 to 3.0.6, 2.9 to 2.9.8, 2.8 to 2.8.12, 2.7 to 2.7.16 and earlier unsupported versions
Versions fixed:3.1.3, 3.0.7, 2.9.9 and 2.7.17
Reported by:Andrew Nicols
Issue no.:MDL-51347
CVE identifier:CVE-2016-8644
Changes (master):

