A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.1.14"
},
{
"introduced": "4.2.0"
},
{
"last_affected": "4.2.11"
},
{
"introduced": "4.3.0"
},
{
"last_affected": "4.3.8"
},
{
"introduced": "4.4.0"
},
{
"last_affected": "4.4.4"
}
]
}