mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-12-16 01:30
Updated : 2020-12-01 14:43
NVD link : CVE-2009-4299
Mitre link : CVE-2009-4299
CVE.ORG link : CVE-2009-4299
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-264
Permissions, Privileges, and Access Controls