A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | 3.5.0 (including) | 3.5.8 (including) |
Moodle | Moodle | 3.6.0 (including) | 3.6.6 (including) |
Moodle | Moodle | 3.7.0 (including) | 3.7.2 (including) |
Moodle | Ubuntu | bionic | * |
Moodle | Ubuntu | disco | * |
Moodle | Ubuntu | eoan | * |
Moodle | Ubuntu | trusty | * |
Moodle | Ubuntu | xenial | * |