Description
mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.
Remediation
References
Related Vulnerabilities
Moodle Credentials Management Errors Vulnerability (CVE-2011-4587)
MySQL CVE-2019-2805 Vulnerability (CVE-2019-2805)
WordPress Plugin Embed Swagger Cross-Site Scripting (1.0.0)
WordPress Plugin Tigris for Salesforce PHP Object Injection (1.1.3)
WordPress Plugin Custom Search by BestWebSoft Unspecified Vulnerability (1.21)