Description
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2) badges/view.php.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Other Vulnerability (CVE-2003-0253)
WordPress Plugin Woocommerce-Recent Purchases Local File Inclusion (1.0.1)
Oracle Database Server CVE-2015-4857 Vulnerability (CVE-2015-4857)
Perl Improper Certificate Validation Vulnerability (CVE-2023-31484)
WordPress Plugin Google 'Plus one' Button by kms Multiple Vulnerabilities (1.5.0)