ZeroHour

CVE-2021-43560

CVSS 3.1
5.3 medium
EPSS
<1%p60
Published
()
Modified
Description

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

Vendors
moodlefedoraproject
Products
moodle, extra packages for enterprise linux, fedora
Weakness
CWE-863, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.