Description
Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin GiveWP-Donation and Fundraising Platform Multiple Vulnerabilities (2.21.2)
Liferay Portal Observable Discrepancy Vulnerability (CVE-2024-25146)
WordPress CVE-2012-0937 Vulnerability (CVE-2012-0937)
Oracle Database Server Other Vulnerability (CVE-2005-3444)
WordPress Plugin YITH WooCommerce Ajax Search Security Bypass (1.6.9)