The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
{
"versions": [
{
"introduced": "3.9.0"
},
{
"fixed": "3.9.19"
},
{
"introduced": "3.11.0"
},
{
"fixed": "3.11.12"
},
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.0-NA"
}
]
}