Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.