Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
- | 4.3.0-rc2 |
| moodle / moodle | 4.2.0 | 4.2.3 |
| moodle / moodle | 4.1.0 | 4.1.6 |
| moodle / moodle | 4.0.0 | 4.0.11 |
| moodle / moodle | 3.11.0 | 3.11.17 |
| moodle / moodle | - | 3.9.24 |
| fedoraproject / extra_packages_for_enterprise_linux | 7.0 | 7.0.x |
| fedoraproject / fedora | 38 | 38.x |