CVE-2019-3852 | Moodle up to 3.6.2 get_with_capability_join/get_users_by_capability access control (Nessus ID 261359)
A vulnerability described as critical has been identified in Moodle up to 3.6.2. Affected by this issue is the function get_with_capability_join/get_users_by_capability. Such manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2019-3852. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.