A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
2021-11-22T16:15:08.337
2024-11-21T06:29:26.300
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | ≤ 3.8.8 | Yes |
Application | moodle | moodle | < 3.9.11 | Yes |
Application | moodle | moodle | < 3.10.8 | Yes |
Application | moodle | moodle | < 3.11.4 | Yes |
Application | fedoraproject | extra_packages_for_enterprise_linux | 7.0 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |