Description
enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.
Remediation
References
Related Vulnerabilities
WordPress Plugin FreeMind WP Browser Cross-Site Request Forgery (1.2)
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-48008)
WordPress Plugin SEO Redirection-301 Redirect Manager SQL Injection (3.5)
MediaWiki CVE-2023-45367 Vulnerability (CVE-2023-45367)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2016-7053)