Moodle Ability to delete glossary entries that belong to another glossary
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Apr 24, 2024
Package
Affected versions
>= 3.7, < 3.7.1
>= 3.6, < 3.6.5
>= 3.5, < 3.5.7
Patched versions
3.7.1
3.6.5
3.5.7
Description
Published by the National Vulnerability Database
Jul 31, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Apr 24, 2024
Last updated
Apr 24, 2024
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
References