Description
mod/assign/locallib.php in the assignment module in Moodle 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download (aka downloadall) requests, which allows remote authenticated users to read other users' assignments by leveraging the student role.
Remediation
References
Related Vulnerabilities
WordPress Plugin Email Before Download Unspecified Vulnerability (6.9.3)
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31986)
WordPress Plugin Video.js-HTML5 Video Player for Wordpress Cross-Site Scripting (4.5.0)
IBMHttpServer Improper Input Validation Vulnerability (CVE-2023-26281)