VDB
Sign up
MEDIUM6.5

GHSA-5p2x-8427-9fgp

Moodle Improper Access Control vulnerability

Details

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/moodle/moodle
Introduced in: 0

No fixed version published yet for moodle/moodle (composer). Pin to a known-safe version or switch to an alternative.

References