Bug 2263853 (CVE-2024-1439) - CVE-2024-1439 moodle: Inadequate access control
Summary: CVE-2024-1439 moodle: Inadequate access control
Keywords:
Status: NEW
Alias: CVE-2024-1439
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2263854 2263855
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-02-12 12:46 UTC by ybuenos
Modified: 2024-02-12 12:46 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description ybuenos 2024-02-12 12:46:32 UTC
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

https://www.incibe.es/en/incibe-cert/notices/aviso/inadequate-access-control-vulnerability-moodle

Comment 1 ybuenos 2024-02-12 12:46:48 UTC
Created moodle tracking bugs for this issue:

Affects: epel-all [bug 2263854]
Affects: fedora-all [bug 2263855]


Note You need to log in before you can comment on or make changes to this bug.