Description
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
Remediation
References
Related Vulnerabilities
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2022-42130)
WordPress Plugin AJAX Post Search 'srch_txt' Parameter SQL Injection (1.2)
Magento Improper Authentication Vulnerability (CVE-2015-3457)
Next.js Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2022-36046)