Description
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
Remediation
References
Related Vulnerabilities
MongoDb Out-of-bounds Write Vulnerability (CVE-2021-32040)
WordPress Plugin FancyBox for WordPress Security Bypass (3.0.2)
Moodle Improper Input Validation Vulnerability (CVE-2012-6101)
MySQL CVE-2013-0384 Vulnerability (CVE-2013-0384)
Oracle Application Server CVE-2006-3714 Vulnerability (CVE-2006-3714)