Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4701
HistoryJul 26, 2017 - 9:22 a.m.

Bypass Access Restrictions

2017-07-2609:22:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.001

Percentile

46.9%

Moodle is vulnerable to bypassing of access restrictions. The bypass is possible because tag/tag_autocomplete.php ignores the moodle/tag:edit capability before adding a tag, allowing any authenticated users to launch attack through an AJAX request.

EPSS

0.001

Percentile

46.9%