MEDIUM6.5
GHSA-5p2x-8427-9fgp
Moodle Improper Access Control vulnerability
Details
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/moodle/moodle
Introduced in:
0No fixed version published yet for moodle/moodle (composer). Pin to a known-safe version or switch to an alternative.