← Back

CVE-2024-1439

nvd nist
Published: Feb 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

Affected (1)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.2.11

References (2)

Timeline

No history available yet.