Description
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2020-2968 Vulnerability (CVE-2020-2968)
Atlassian Jira Improper Authentication Vulnerability (CVE-2021-41308)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2017-8385)
Liferay DXP Insecure Default Initialization of Resource Vulnerability (CVE-2023-33949)
Ruby on Rails Inefficient Regular Expression Complexity Vulnerability (CVE-2023-22792)