Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
{ "cpes": [ "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*" ], "severity": "Medium" }