Description
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ultimate Membership Pro SQL Injection (6.4)
MongoDb Incorrect Authorization Vulnerability (CVE-2020-7921)
WordPress Plugin Mikiurl WordPress Eklentisi Cross-Site Request Forgery (2.0)
WordPress Plugin Archivist-Custom Archive Templates Multiple Vulnerabilities (1.7.4)
WordPress Plugin Tidio Live Chat Cross-Site Request Forgery (4.1.0)