Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-1439

Опубликовано: 12 фев. 2024
Источник: debian
EPSS Низкий

Описание

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
moodleremovedpackage

EPSS

Процентиль: 22%
0.00068
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
nvd
больше 1 года назад

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

CVSS3: 6.5
github
больше 1 года назад

Moodle Improper Access Control vulnerability

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость виртуальной обучающей среды Moodle, связанная с недостатками контроля доступа, позволяющая нарушителю с ролью student создавать произвольные события

EPSS

Процентиль: 22%
0.00068
Низкий