CVE-2012-2367: Medium severity moodle vulnerability
Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2367?
CVE-2012-2367 has a severity rating that indicates potential risk to user data and unauthorized calendar entry manipulation.
How do I fix CVE-2012-2367?
To fix CVE-2012-2367, upgrade your Moodle installation to versions 1.9.18, 2.0.9, 2.1.6, or 2.2.3 or later.
Which versions of Moodle are affected by CVE-2012-2367?
CVE-2012-2367 affects Moodle versions 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3.
Who can exploit CVE-2012-2367?
Remote authenticated users can exploit CVE-2012-2367 to bypass calendar entry permissions.
What is the impact of CVE-2012-2367 on Moodle systems?
The impact of CVE-2012-2367 allows unauthorized calendar entry creation, potentially leading to data integrity issues.