Insufficient capability checks made it possible to disable badges a user does not have permission to access.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://moodle.org/mod/forum/discuss.php?d=466148 | vendor advisory |
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84239 | patch |