Description
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a rule.
Remediation
References
Related Vulnerabilities
Drupal Core 4.5.x Multiple Vulnerabilities (4.5.0 - 4.5.5)
Apache HTTP Server Other Vulnerability (CVE-2003-0993)
Dot CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-17422)
Oracle HTTP Server Use After Free Vulnerability (CVE-2019-10082)
Oracle Database Server CVE-2006-0291 Vulnerability (CVE-2006-0291)