CVE-2011-4285
Publication date 16 July 2012
Last updated 24 July 2024
Ubuntu priority
Description
The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.