CVE-2015-3273
22.02.2016, 05:59
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group authorization.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 2.9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References