Description
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
Remediation
References
Related Vulnerabilities
Moodle CVE-2021-32473 Vulnerability (CVE-2021-32473)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5297)
WordPress Plugin Terillion Reviews Profile Id Cross-Site Scripting (1.1)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10101)
WordPress Plugin ARMember-Content Restriction & Membership Security Bypass (1.4)