Description
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service.
Remediation
References
Related Vulnerabilities
Drupal Core 6.x Local File Inclusion (6.0 - 6.9)
MediaWiki Improper Input Validation Vulnerability (CVE-2014-1610)
Oracle Application Server CVE-2006-3714 Vulnerability (CVE-2006-3714)
WordPress 3.9.1 Multiple Vulnerabilities (3.9 - 3.9.1)
WordPress Plugin WP Smart Image II Cross-Site Scripting (0.2)