Permissions, Privileges, and Access Controls in Moodle - CVE-2019-14829
Published: September 16, 2019
Moodle
Detailed vulnerability description
The vulnerability allows a remote authenticated user to gain access to sensitive information.
The vulnerability exists due to the activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode. A remote authenticated user can gain access to sensitive information.