A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
Workaround:
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2304259 | issue tracking permissions required |
https://moodle.org/mod/forum/discuss.php?d=461199 | vendor advisory |