Description
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
Remediation
References
Related Vulnerabilities
Drupal Core 6.x Multiple Security Bypass Vulnerabilities (6.0 - 6.4)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2097)
WordPress Plugin MetaSlider Cross-Site Scripting (3.17.1)
Roundcube Cross-site Request Forgery (CSRF) Vulnerability (CVE-2016-4069)
OpenSSL Improper Input Validation Vulnerability (CVE-2014-3513)