Description
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a manage-files button in a text editor.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Searchable Data Entry System Security Bypass (1.7.1)
WordPress Plugin Bilingual Linker Cross-Site Scripting (2.1.1)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-15098)
WordPress Plugin mTouch Quiz Multiple Vulnerabilities (3.1.2)