CVE-2021-43560: Medium severity moodle vulnerability
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43560?
CVE-2021-43560 has a medium severity due to insufficient capability checks allowing unauthorized access to other users' calendar actions.
How do I fix CVE-2021-43560?
You can fix CVE-2021-43560 by upgrading to Moodle version 3.11.4, 3.10.8, or 3.9.11.
Which versions of Moodle are affected by CVE-2021-43560?
Moodle versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10, and earlier unsupported versions are affected by CVE-2021-43560.
What type of vulnerability is CVE-2021-43560?
CVE-2021-43560 is a security vulnerability that pertains to insufficient capability checks in the Moodle calendar feature.
Who should be concerned about CVE-2021-43560?
Administrators of Moodle installations running the affected versions should be concerned about CVE-2021-43560 and take action to secure their systems.