Description
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
Remediation
References
Related Vulnerabilities
WordPress Plugin User Control SQL Injection (2.1.0)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4522)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5497)
Liferay DXP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606)