Moodle has Incorrect Default Permissions
Moderate severity GitHub Reviewed Published Mar 7, 2023 to the GitHub Advisory Database • Updated Mar 13, 2023
Package
moodle/moodle (Composer)
Affected versions
>= 3.11.0-beta, < 3.11.1
>= 3.10.0-beta, < 3.10.5
< 3.9.8
Patched versions
3.11.1
3.10.5
3.9.8
Description
Published by the National Vulnerability DatabaseMar 6, 2023
Published to the GitHub Advisory Database Mar 7, 2023
Reviewed Mar 8, 2023
Last updated Mar 13, 2023
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
References