Description
mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.
Remediation
References
Related Vulnerabilities
Jenkins Incorrect Authorization Vulnerability (CVE-2021-21670)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-2572)
Moodle Improper Authentication Vulnerability (CVE-2011-4590)
WordPress Plugin WP Offload SES Lite Cross-Site Scripting (1.4.4)
TYPO3 Improper Input Validation Vulnerability (CVE-2011-4902)