A vulnerability was found in moodle before version 3.6.3. The getwithcapabilityjoin and getusersbycapability functions were not taking context freezing into account when checking user capabilities
{ "binaries": [ { "binary_version": "3.0.3+dfsg-0ubuntu1", "binary_name": "moodle" } ] }