A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3872 A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
Github GHSA Github GHSA GHSA-g39c-mccf-rxjv Moodle Insecure direct object reference (IDOR) in a calendar web service
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2024-08-04T04:03:08.485Z

Reserved: 2021-11-09T00:00:00

Link: CVE-2021-43560

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-22T16:15:08.337

Modified: 2024-11-21T06:29:26.300

Link: CVE-2021-43560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.