Description
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Remediation
References
Related Vulnerabilities
Moodle Configuration Vulnerability (CVE-2011-4585)
Apache HTTP Server Insertion of Sensitive Information into Log File Vulnerability (CVE-2001-1556)
Apache HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2024-40898)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.2.0.727)