Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Moodle | * | 3.9.24 (excluding) |
Moodle | Moodle | 3.11.0 (including) | 3.11.17 (excluding) |
Moodle | Moodle | 4.0.0 (including) | 4.0.11 (excluding) |
Moodle | Moodle | 4.1.0 (including) | 4.1.6 (excluding) |
Moodle | Moodle | 4.2.0 (including) | 4.2.3 (excluding) |
Moodle | Ubuntu | bionic | * |
Moodle | Ubuntu | trusty | * |
Moodle | Ubuntu | xenial | * |