A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
{ "nvd_published_at": "2019-06-26T19:15:00Z", "cwe_ids": [ "CWE-285" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-26T20:46:23Z" }