Inadequate access control vulnerability in Moodle
Vulnerability Description
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1439
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- David Utón Amaya
References
More from Moodle
View All →Affected Vendor
Moodle
View all reports →