CVE-2021-36400: Medium severity moodle vulnerability
Published Mar 6, 2023
·Updated
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
Affected Software
3 affected components
Moodle moodle<3.9.8
Moodle moodle>=3.10.0<3.10.5
Moodle moodle>=3.11.0<3.11.1
Remediation
Patch Available
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-36400?
CVE-2021-36400 is a vulnerability in Moodle that allows for the removal of other users' calendar URL subscriptions.
2
How does the vulnerability in Moodle work?
The vulnerability in Moodle is caused by insufficient capability checks, which allow an attacker to remove other users' calendar URL subscriptions.
3
What versions of Moodle are affected by CVE-2021-36400?
Versions 3.9.8, 3.10.0 to 3.10.5, and 3.11.0 to 3.11.1 of Moodle are affected by CVE-2021-36400.
4
What is the severity of CVE-2021-36400?
CVE-2021-36400 has a severity score of 5.3, making it a medium severity vulnerability.
5
How can I fix CVE-2021-36400 in Moodle?
To fix CVE-2021-36400 in Moodle, you should upgrade to a version that is not affected by the vulnerability.