Description
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Inventory Manager Cross-Site Scripting (1.7.8)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-9591)
WordPress Plugin AppPresser-Mobile App Framework Security Bypass (4.3.2)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-28644)