Description
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
Remediation
References
Related Vulnerabilities
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1041)
Oracle Database Server Deserialization of Untrusted Data Vulnerability (CVE-2018-14719)
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.15)
WordPress Plugin Raygun4WP Cross-Site Scripting (1.8.2)
Moodle Uncontrolled Recursion Vulnerability (CVE-2021-36395)