Total vulnerabilities in the database
The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
Software | From | Fixed in |
---|---|---|
moodle / moodle | 2.0.1 | 2.0.1.x |
moodle / moodle | 2.0.0 | 2.0.0.x |