A vulnerability was found in moodle before versions 3.6.3, 3.5.5...
Vulnerability Description
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3848
Credits & Attribution
No credits recorded in the NVD database.
References
More from [UNKNOWN]
View All →Affected Vendor
[UNKNOWN]
View all reports →