Description
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.
Remediation
References
Related Vulnerabilities
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10321)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.35)
WordPress Plugin Wordfence Security-Firewall & Malware Scan Unspecified Vulnerability (5.3.2)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5471)