CVE-2012-2367
N/A
N/A
Summary
Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://osvdb.org/82074
- http://openwall.com/lists/oss-security/2012/05/23/2
- http://www.securityfocus.com/bid/53626
- https://moodle.org/mod/forum/discuss.php?d=203057
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-18335
References
- http://osvdb.org/82074
- http://openwall.com/lists/oss-security/2012/05/23/2
- http://www.securityfocus.com/bid/53626
- https://moodle.org/mod/forum/discuss.php?d=203057
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-18335
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.