Moodle Exposure of Resource to Wrong Sphere Vulnerability - CVE-2017-7490
In Moodle 2.x and 3.x searching of arbitrary blogs is possible because a capability check is missing.
In Moodle 2.x and 3.x searching of arbitrary blogs is possible because a capability check is missing.