The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
{ "nvd_published_at": "2023-02-17T20:15:00Z", "github_reviewed_at": "2023-03-02T18:16:20Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-284" ] }