CVE-2022-0333: Medium severity moodle vulnerability
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0333?
CVE-2022-0333 is a vulnerability found in Moodle that allows managers to access or modify any calendar event, but should have been restricted from accessing user level events.
What versions of Moodle are affected by CVE-2022-0333?
Moodle versions 3.11 to 3.11.4, 3.10 to 3.10.8, and 3.9 to 3.9.11 are affected by CVE-2022-0333.
What is the severity of CVE-2022-0333?
CVE-2022-0333 has a severity rating of 3.8, which is considered medium.
How can I fix CVE-2022-0333?
To fix CVE-2022-0333, you should update Moodle to versions 3.9.11, 3.10.8, or 3.11.5, depending on the version you are running.
Where can I find more information about CVE-2022-0333 vulnerability in Moodle?
You can find more information about CVE-2022-0333 in Moodle on the following references: [1] [2] [3].