Description
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Survey Plus Security Bypass (1.0)
WordPress Plugin Thrive Ultimatum Security Bypass (2.3.9.3)
WordPress Plugin WordPress Filter Gallery Cross-Site Scripting (0.1.5)
MySQL CVE-2012-0489 Vulnerability (CVE-2012-0489)
WordPress Plugin Newsletter-Send awesome emails from WordPress Cross-Site Scripting (7.8.9)