Lucene search

K
osvGoogleOSV:GHSA-G39C-MCCF-RXJV
HistoryMay 24, 2022 - 7:21 p.m.

Moodle Insecure direct object reference (IDOR) in a calendar web service

2022-05-2419:21:10
Google
osv.dev
15
moodle
idor
insecure direct object reference
calendar
capability checks

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

39.2%

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users’ calendar action events.

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

39.2%