#VU82194 Improper access control in Moodle - CVE-2023-5549
Published: October 18, 2023
Moodle
moodle.org
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to insufficient capability checks when updating the parent of a course category. A remote user can move categories a they have permission to manage, to a parent category they have not have the capability to manage.