Description
lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2006-5362)
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36156)
TYPO3 Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2014-9508)
WordPress Plugin WPshop-eCommerce Arbitrary File Upload (1.3.9.5)