A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
{ "binaries": [ { "binary_version": "3.0.3+dfsg-0ubuntu1", "binary_name": "moodle" } ] }