Description
Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Button Plugin MaxButtons Cross-Site Scripting (6.18)
ProjectSend Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2023-53905)
MySQL CVE-2018-3212 Vulnerability (CVE-2018-3212)
Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-40898)