A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=2021519 Issue Tracking Third Party Advisory
https://moodle.org/mod/forum/discuss.php?d=429100 Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: fedora

Published: 2021-11-22T16:00:22

Updated: 2021-11-22T16:00:22

Reserved: 2021-11-09T00:00:00


Link: CVE-2021-43560

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-11-22T16:15:08.337

Modified: 2022-12-21T15:01:19.963


Link: CVE-2021-43560

JSON object: View

cve-icon Redhat Information

No data.