Description
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
Remediation
References
Related Vulnerabilities
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32731)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2016-5734)
PHP Out-of-bounds Write Vulnerability (CVE-2022-31627)
Drupal Incorrect Authorization Vulnerability (CVE-2017-6377)