#VU43834 Permissions, Privileges, and Access Controls in Moodle - CVE-2011-4584
Published: July 20, 2012 / Updated: August 11, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote #AU# to manipulate data.
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.