The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.