Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | 2.3.0 (including) | 2.3.0 (including) |
Moodle | Moodle | 2.3.1 (including) | 2.3.1 (including) |
Moodle | Moodle | 2.3.2 (including) | 2.3.2 (including) |
Moodle | Ubuntu | hardy | * |
Moodle | Ubuntu | upstream | * |