Description
A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.
Remediation
References
Related Vulnerabilities
Claroline Other Vulnerability (CVE-2005-1375)
WordPress Plugin Open Graph for Facebook, Google+ and Twitter Card Tags Cross-Site Scripting (2.2.4)
WordPress Plugin Subscribe To Comments Reloaded Cross-Site Scripting (150611)
Apache HTTP Server Improper Input Validation Vulnerability (CVE-2017-15715)