CVE-2012-0793 - Huggable Fungus
Description
Moodle 1.9.x before 1.9.16 2.0.x before 2.0.7 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=783532 http://git.moodle.org/gw?p=moodle.git;a=commit;h=90911c4ff98dc2078a3acef5ddf5a1a8f7e20ba5 http://moodle.org/mod/forum/discuss.php?d=194012 http://www.debian.org/security/2012/dsa-2421