A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14879 | issue tracking exploit third party advisory |