mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-12-15 17:30
Updated : 2020-12-01 06:43
NVD link : CVE-2009-4299
Mitre link : CVE-2009-4299
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
moodle
- moodle