Description
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.
Remediation
References
Related Vulnerabilities
WordPress Plugin CP Contact Form with PayPal Cross-Site Scripting (1.2.97)
Oracle Application Server Other Vulnerability (CVE-2004-1877)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2016-6303)
Oracle JRE CVE-2017-10348 Vulnerability (CVE-2017-10348)
Jboss EAP Improper Access Control Vulnerability (CVE-2013-4213)