A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
| Software | From | Fixed in |
|---|---|---|
| moodle / moodle | 4.1.0 | 4.1.21 |
| moodle / moodle | 4.4.0 | 4.4.11 |
| moodle / moodle | 4.5.0 | 4.5.7 |
| moodle / moodle | 5.0.0 | 5.0.3 |