Description
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
Remediation
References
Related Vulnerabilities
SharePoint Improper Input Validation Vulnerability (CVE-2019-0957)
WordPress Plugin Batch Cat Security Bypass (0.3)
Nexus Repository Manager CVE-2019-15893 Vulnerability (CVE-2019-15893)
WordPress 3.9.x Cross-Site Request Forgery (3.9 - 3.9.26)
WordPress Plugin Email Encoder-Protect Email Addresses Cross-Site Scripting (2.1.1)