Description
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
Remediation
References
Related Vulnerabilities
CubeCart Improper Authentication Vulnerability (CVE-2014-2341)
Joomla! Core 1.5.x Cross-Site Scripting (1.5.0 - 1.5.11)
Internet Information Services Other Vulnerability (CVE-1999-0253)
SharePoint Improper Privilege Management Vulnerability (CVE-2021-1719)
WordPress Plugin WP Database Reset Multiple Security Bypass Vulnerabilities (3.1)