In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
During installation, installed file permissions are set to allow anyone to modify those files.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://moodle.org/mod/forum/discuss.php?d=424806 | patch vendor advisory |