A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
2022-01-25T20:15:08.803
2024-11-21T06:38:23.907
Modified
CVSSv3.1: 3.8 (LOW)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | ≤ 3.8.9 | Yes |
Application | moodle | moodle | < 3.9.12 | Yes |
Application | moodle | moodle | < 3.10.9 | Yes |
Application | moodle | moodle | < 3.11.5 | Yes |