Insufficient capability checks when updating the parent of a course category
CVE-2023-5549
5.3MEDIUM
What is CVE-2023-5549?
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
Affected Version(s)
moodle 4.2.3
moodle 4.1.6
moodle 4.0.11