Looking for the vulnerability index of Invicti's legacy products?
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4297) - Vulnerability Database

Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4297)

Description

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

References