Description
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2022-29108 Vulnerability (CVE-2022-29108)
WordPress Plugin MiwoFTP-File & Folder Manager Arbitrary File Download (1.0.5)
WordPress Plugin wp audio gallery playlist 'playlist.php' SQL Injection (0.12)
WordPress Plugin Controlled Admin Access Security Bypass (1.5.5)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2019-11039)