Description
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
Remediation
References
Related Vulnerabilities
WordPress Plugin Mapplic-Custom Interactive Map Server-Side Request Forgery (6.1)
WordPress Plugin WP DS FAQ Plus Cross-Site Scripting (1.4.1)
WordPress Plugin AddToAny Share Buttons Cross-Site Scripting (1.6.6)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-0813)