Description
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
Remediation
References
Related Vulnerabilities
Oracle JRE Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0422)
Apache Tomcat Resource Management Errors Vulnerability (CVE-2012-4534)
WordPress Plugin Arigato Autoresponder and Newsletter Multiple Unspecified Vulnerabilities (2.4.2)
WordPress Plugin Simplr Registration Form Plus+ Privilege Escalation (2.4.3)