Description
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-2784 Vulnerability (CVE-2018-2784)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2017-12171)
MediaWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-31547)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2246)
Oracle Database Server CVE-2020-2510 Vulnerability (CVE-2020-2510)