Description
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.
Remediation
References
Related Vulnerabilities
WordPress Plugin FireCask Like & Share Button Cross-Site Scripting (1.1.5)
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-1892)
MySQL CVE-2013-1548 Vulnerability (CVE-2013-1548)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2022-41766)