Description
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Remediation
References
Related Vulnerabilities
Phusion Passenger Other Vulnerability (CVE-2014-1831)
OpenSSL Cryptographic Issues Vulnerability (CVE-2013-6449)
Drupal Insufficient Verification of Data Authenticity Vulnerability (CVE-2016-9450)
WordPress Plugin Service Finder-Provider and Business Listing Local File Disclosure (3.0)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2017-1000353)