CVE Vulnerabilities

CVE-2024-1439

Published: Feb 12, 2024 | Modified: Oct 10, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle * 4.2.11 (including)
Moodle Ubuntu bionic *
Moodle Ubuntu trusty *
Moodle Ubuntu xenial *

References